CVE-2025-54156: Santesoft Sante PACS Server Cleartext Transmission of Sensitive Information
Published Aug 18, 2025
·Updated
The Sante PACS Server Web Portal sends credential information without encryption.
Affected Software
2 affected components
Santesoft Sante PACS Server
Santesoft Sante PACS Server<4.2.3
Remediation
Information
Santesoft recommends users update PACS Server to Version 4.2.3 or later https://santesoft.com/win/sante-pacs-server/download.html .
Event History
Aug 18, 2025
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54156?
CVE-2025-54156 is classified as a high-severity vulnerability due to the potential exposure of sensitive credential information.
2
How do I fix CVE-2025-54156?
To fix CVE-2025-54156, ensure that all credential information sent by the Sante PACS Server Web Portal is encrypted.
3
What systems are affected by CVE-2025-54156?
CVE-2025-54156 affects the Santesoft Sante PACS Server and its web portal functionality.
4
What are the risks associated with CVE-2025-54156?
The primary risk of CVE-2025-54156 is unauthorized access to sensitive credential information, which may lead to further security breaches.
5
Is there a patch available for CVE-2025-54156?
Currently, a specific patch for CVE-2025-54156 has not been released, and users are advised to implement encryption workarounds.