CVE-2025-54156

7.4

Santesoft · Sante PACS Server

The Sante PACS Server Web Portal transmits sensitive credential information in cleartext, exposing authentication details to interception by unauthorized parties on the network.

Executive summary

A critical vulnerability in Santesoft Sante PACS Server allows for the interception of sensitive credentials due to a lack of encryption during transmission.

Vulnerability

This flaw involves the cleartext transmission of sensitive information (CWE-319) over the network. The vulnerability is unauthenticated, meaning any network-adjacent attacker can capture credentials without requiring prior access to the system.

Business impact

The ability for an attacker to intercept administrative or user credentials poses a significant risk to the confidentiality and integrity of medical imaging data. Given the CVSS score of 7.4, this vulnerability represents a high risk that could lead to unauthorized access to the PACS environment, potentially resulting in data exfiltration or unauthorized manipulation of patient records.

Remediation

Immediate Action: Update the Sante PACS Server software to version 4.2.3 or later as specified in the vendor advisory.

Proactive Monitoring: Review network traffic logs for suspicious patterns and ensure that all web portal communications are forced over encrypted channels where possible.

Compensating Controls: Implement network segmentation to isolate the PACS server and utilize a Web Application Firewall or VPN to encrypt traffic if an immediate software update is operationally delayed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk of credential interception in a medical environment necessitates prompt action. Administrators should prioritize the upgrade to version 4.2.3 immediately to eliminate the cleartext transmission of credentials and secure the authentication process against network-based sniffing attacks.

Sources

Originally found and disclosed by Chizuru Toyama of TXOne Networks reported these vulnerabilities to CISA., per the CVE Program record.