CVE-2025-2265: Santesoft Sante PACS Server HTTP.db SHA1 Hash Truncation
The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the SQLite database HTTP.db. However, the number of hash bytes encoded and stored is truncated if the hash contains a zero byte
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2265?
CVE-2025-2265 has a high severity rating due to its potential impact on the security of user passwords.
How do I fix CVE-2025-2265?
To fix CVE-2025-2265, ensure you update to the latest version of Sante PACS Server released by Santesoft that addresses this vulnerability.
What are the risks associated with CVE-2025-2265?
The risks of CVE-2025-2265 include unauthorized access to user accounts due to weak password storage methods.
Which versions of Sante PACS Server are affected by CVE-2025-2265?
CVE-2025-2265 affects all versions of Sante PACS Server that utilize the vulnerable password storage method.
What steps should be taken if I believe my system is vulnerable to CVE-2025-2265?
If you suspect your system is vulnerable to CVE-2025-2265, immediately update the software and review user account security practices.