CVE-2025-2263
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-2263 is a stack-based buffer overflow vulnerability affecting the Sante PACS Server.exe web application. The issue lies in the handling of usernames and passwords during login. When the OpenSSL function EVP_DecryptUpdate is used for decryption, a fixed 0x80-byte buffer is provided as the output buffer. An unauthenticated remote attacker who supplies a long encrypted username or password can exploit this vulnerability by overwriting adjacent memory, potentially leading to arbitrary code execution or denial of service. This can pose a serious threat to the security and integrity of the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sante PACS Server
Affected Vendors
- Santesoft LTD