CVE-2025-53948: Santesoft Sante PACS Server Double Free
Published Aug 18, 2025
·Updated
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.
Affected Software
2 affected components
Santesoft Sante PACS Server
Santesoft Sante PACS Server<4.2.3
Remediation
Information
Santesoft recommends users update PACS Server to Version 4.2.3 or later https://santesoft.com/win/sante-pacs-server/download.html .
Event History
Aug 18, 2025
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53948?
CVE-2025-53948 is classified as a denial-of-service vulnerability.
2
How do I fix CVE-2025-53948?
To fix CVE-2025-53948, ensure that the Sante PACS Server is updated to the latest version released by Santesoft.
3
What type of attacks can CVE-2025-53948 cause?
CVE-2025-53948 can lead to a denial-of-service condition by crashing the main thread of the Sante PACS Server.
4
Is authentication required to exploit CVE-2025-53948?
No, CVE-2025-53948 can be exploited without any authentication.
5
What is the impact of CVE-2025-53948 on Sante PACS Server?
The impact of CVE-2025-53948 on Sante PACS Server is a forced crash that requires a manual restart of the application.