CVE-2025-2263 Details
Description
During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based buffer is passed to the function as the output buffer. A stack-based buffer overflow exists if a long encrypted username or password is supplied by an unauthenticated remote attacker.
A stack-based buffer overflow vulnerability has been identified in Sante PACS Server version 4.1.0. During the login process, the application uses the OpenSSL function EVP_DecryptUpdate to decrypt the username and password. A fixed 128-byte stack buffer is provided as the output buffer for the decryption process. If an unauthenticated remote attacker sends a long encrypted username or password, it can overflow the stack buffer, potentially leading to arbitrary code execution.
Users are advised to upgrade to Sante PACS Server version 4.2.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tenable.com/security/research/tra-2025-08 | CISA-ADP | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2025-08 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| santesoft sante pacs server | 4.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2025 | Initial Analysis | [email protected] |
| Mar 14, 2025 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | New CVE Received | [email protected] |