CVE-2025-0896

CRITICAL

Orthanc < 1.5.8 - Unauthenticated Remote Access

Title source: llm
STIX 2.1

Description

Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0235
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
orthanc-server/orthanc < 1.5.8
Published Feb 13, 2025
Tracked Since Feb 18, 2026