CVE-2025-2264

HIGH EXPLOITED NUCLEI

Sante PACS Server Path Traversal (CVE-2025-2264)

Title source: metasploit

Description

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

Exploits (1)

metasploit WORKING POC
by Michael Heinzl, Tenable · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/pacsserver_traversal.rb

Nuclei Templates (1)

Sante PACS Server.exe - Path Traversal Information Disclosure
HIGHVERIFIEDby DhiyaneshDK
Shodan: http.favicon.hash:1185161484

Scores

CVSS v3 7.5
EPSS 0.6385
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2025-07-31
CWE
CWE-22
Status published
Products (1)
santesoft/sante_pacs_server 4.1.0
Published Mar 13, 2025
Tracked Since Feb 18, 2026