CVE-2025-2265
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 13, 2025
CWE ID 916
Summary
CVE-2025-2265 is a vulnerability affecting the Sante PACS Server.exe. The issue lies in the way passwords are stored in the SQLite database HTTP.db. Instead of storing the SHA1 hash of the password in its entirety, the number of hash bytes encoded and stored is truncated if the hash contains a zero byte, potentially allowing an attacker to bypass authentication by manipulating the stored password hash. This flaw can lead to unauthorized access to the system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sante PACS Server
Affected Vendors
- Santesoft LTD