CVE-2025-2264

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
References
Link Resource
https://www.tenable.com/security/research/tra-2025-08 Exploit Third Party Advisory
https://www.tenable.com/security/research/tra-2025-08 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:santesoft:sante_pacs_server:4.1.0:*:*:*:*:*:*:*

History

03 Apr 2025, 18:19

Type Values Removed Values Added
First Time Santesoft
Santesoft sante Pacs Server
References () https://www.tenable.com/security/research/tra-2025-08 - () https://www.tenable.com/security/research/tra-2025-08 - Exploit, Third Party Advisory
CPE cpe:2.3:a:santesoft:sante_pacs_server:4.1.0:*:*:*:*:*:*:*

14 Mar 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de divulgación de información de Path Traversal en "Sante PACS Server.exe". Un atacante remoto no autenticado puede explotarla para descargar archivos arbitrarios en la unidad de disco donde está instalada la aplicación.
References () https://www.tenable.com/security/research/tra-2025-08 - () https://www.tenable.com/security/research/tra-2025-08 -

13 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 17:15

Updated : 2025-04-03 18:19


NVD link : CVE-2025-2264

Mitre link : CVE-2025-2264

CVE.ORG link : CVE-2025-2264


JSON object : View

Products Affected

santesoft

  • sante_pacs_server
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')