Home

Description

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

PUBLISHED Reserved 2025-03-12 | Published 2025-03-13 | Updated 2025-03-14 | Assigner tenable




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

4.1.0
affected

4.2.0
unaffected

References

www.tenable.com/security/research/tra-2025-08 exploit

www.tenable.com/security/research/tra-2025-08

cve.org (CVE-2025-2264)

nvd.nist.gov (CVE-2025-2264)

Download JSON