Description
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.
Problem types
Product status
Any version before 4.2.3
Credits
Chizuru Toyama of TXOne Networks reported these vulnerabilities to CISA.
References
www.cisa.gov/...vents/ics-medical-advisories/icsma-25-224-01