ZDI-CAN-21579: ZDI-24-468: Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the DICOM service, which listens on TCP port 11122 by default. When parsing the NAME element of the PATIENT record, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-51637.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21579?
The severity of ZDI-CAN-21579 is critical due to its potential for remote code execution without authentication.
How do I fix ZDI-CAN-21579?
To fix ZDI-CAN-21579, ensure that you update Sante PACS Server PG to the latest version that addresses this vulnerability.
What types of attacks can exploit ZDI-CAN-21579?
ZDI-CAN-21579 can be exploited by remote attackers to execute arbitrary code on vulnerable systems.
Is authentication required to exploit ZDI-CAN-21579?
No, authentication is not required to exploit ZDI-CAN-21579, making it particularly dangerous.
Where can I find more information about ZDI-CAN-21579?
For more information about ZDI-CAN-21579, refer to advisories from the Zero Day Initiative.