ZDI-25-055: Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of URLs in the web server module. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2025-0574.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-055?
ZDI-25-055 is classified as a high severity vulnerability due to its potential to create a denial-of-service condition.
How do I fix ZDI-25-055?
To mitigate ZDI-25-055, apply the latest security patches provided by Sante for the PACS Server.
Who is affected by ZDI-25-055?
ZDI-25-055 affects installations of Sante PACS Server that are exposed to remote attackers.
Is authentication required to exploit ZDI-25-055?
No, authentication is not required to exploit ZDI-25-055, making it easier for attackers to execute the attack.
What type of attack does ZDI-25-055 enable?
ZDI-25-055 enables a denial-of-service attack, impacting the availability of the Sante PACS Server.