CVE-2025-2263

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 13, 2025
Updated: Apr 3, 2025
CWE ID 787
CWE ID 121

Summary

CVE-2025-2263 is a stack-based buffer overflow vulnerability affecting the Sante PACS Server.exe web application. The issue lies in the handling of usernames and passwords during login. When the OpenSSL function EVP_DecryptUpdate is used for decryption, a fixed 0x80-byte buffer is provided as the output buffer. An unauthenticated remote attacker who supplies a long encrypted username or password can exploit this vulnerability by overwriting adjacent memory, potentially leading to arbitrary code execution or denial of service. This can pose a serious threat to the security and integrity of the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sante PACS Server

Affected Vendors

  • Santesoft LTD