CVE-2025-2264
PoC nicheUnauthenticated Path Traversal File Download in Sante PACS Server
Sante PACS Server (Santesoft) contains a path traversal flaw (CWE-22) in its 'Sante PACS Server.exe' component that allows an unauthenticated remote attacker to download arbitrary files from the disk drive where the application is installed. The vulnerability is triggered remotely without any credentials or user interaction, consistent with the network-facing service the product exposes. By supplying crafted traversal paths, an attacker can read sensitive files such as configuration files, credentials, patient records, or system files on the host. Any organization running Sante PACS Server is affected, with the greatest risk to deployments whose service is reachable from the internet, such as clinic, imaging-center, or hospital PACS installations exposed for remote access. There are no confirmed in-the-wild exploits or KEV listings yet, but a public proof of concept exists via Tenable research (TRA-2025-08) and the 30-day EPSS score is high at 34.3% (98th percentile), indicating elevated likelihood of exploitation soon.
What to do: Inventory your environment for Sante PACS Server and apply the vendor's fix identified in Tenable advisory TRA-2025-08; if the fixed version is not yet deployed, restrict network access to the PACS service (firewall/ACL it to trusted internal hosts only) and avoid exposing it directly to the internet. Verify that no attacker-accessible sensitive files (configuration, credentials, patient data) reside on the installation drive, and monitor for exploit activity given the elevated EPSS score.
| Santesoft Sante PACS Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
- Vendors
- santesoft
- Products
- sante pacs server
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.