CVE-2025-2263: Santesoft Sante PACS Server Stack-based Buffer Overflow
During login to the web server in "Sante PACS Server.exe", OpenSSL function EVPDecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based buffer is passed to the function as the output buffer. A stack-based buffer overflow exists if a long encrypted username or password is supplied by an unauthenticated remote attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2263?
CVE-2025-2263 has a medium severity rating due to the potential for a stack-based buffer overflow during user authentication.
How do I fix CVE-2025-2263?
To fix CVE-2025-2263, update Sante PACS Server to the latest version that includes a patch for this vulnerability.
What systems are affected by CVE-2025-2263?
CVE-2025-2263 affects Sante PACS Server software, particularly during the login process.
What potential impact does CVE-2025-2263 have?
Successful exploitation of CVE-2025-2263 could allow an attacker to execute arbitrary code on the affected system.
Is there a workaround for CVE-2025-2263 if I cannot apply a patch immediately?
While a specific workaround is not available for CVE-2025-2263, restricting access to the web server may mitigate the risk until a patch can be applied.