← back
CVE-2025-2264highobserved exploitationCWE-22

Santesoft Sante PACS Server Path Traversal Information Disclosure

70Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.5epss 35%
from disclosure to weapon0 days
Published on NVDMar 13
metasploitMar 13
VulnCheck+140d
exploitation probability
35%top 2% of all CVEs
observed exploitation
yesVulnCheck
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N