CVE-2025-2265

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 13, 2025
CWE ID 916

Summary

CVE-2025-2265 is a vulnerability affecting the Sante PACS Server.exe. The issue lies in the way passwords are stored in the SQLite database HTTP.db. Instead of storing the SHA1 hash of the password in its entirety, the number of hash bytes encoded and stored is truncated if the hash contains a zero byte, potentially allowing an attacker to bypass authentication by manipulating the stored password hash. This flaw can lead to unauthorized access to the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sante PACS Server

Affected Vendors

  • Santesoft LTD