CVE-2025-2264
HIGH EXPLOITED NUCLEISante PACS Server Path Traversal (CVE-2025-2264)
Title source: metasploitExploitation Summary
CVE-2025-2264 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit from researchers including Michael Heinzl, Tenable, including a Metasploit module auxiliary/gather/pacsserver_traversal.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits a path traversal vulnerability (CVE-2025-2264) in Sante PACS Server <= v4.1.0 to retrieve arbitrary files from the system. It sends a crafted HTTP GET request with traversal sequences to access files outside the intended directory.
Description
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
Exploits (1)
This Metasploit module exploits a path traversal vulnerability (CVE-2025-2264) in Sante PACS Server <= v4.1.0 to retrieve arbitrary files from the system. It sends a crafted HTTP GET request with traversal sequences to access files outside the intended directory.
Nuclei Templates (1)
http.favicon.hash:1185161484
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N