CVE-2025-2264
HIGH EXPLOITED NUCLEISante PACS Server Path Traversal (CVE-2025-2264)
Title source: metasploitDescription
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
Exploits (1)
metasploit
WORKING POC
by Michael Heinzl, Tenable · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/pacsserver_traversal.rb
Nuclei Templates (1)
Sante PACS Server.exe - Path Traversal Information Disclosure
HIGHVERIFIEDby DhiyaneshDK
Shodan:
http.favicon.hash:1185161484
Scores
CVSS v3
7.5
EPSS
0.6385
EPSS Percentile
98.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2025-07-31
CWE
CWE-22
Status
published
Products (1)
santesoft/sante_pacs_server
4.1.0
Published
Mar 13, 2025
Tracked Since
Feb 18, 2026