CVE-2025-54156
7.4Santesoft · Sante PACS Server
The Sante PACS Server Web Portal transmits sensitive credential information in cleartext, exposing authentication details to interception by unauthorized parties on the network.
Executive summary
A critical vulnerability in Santesoft Sante PACS Server allows for the interception of sensitive credentials due to a lack of encryption during transmission.
Vulnerability
This flaw involves the cleartext transmission of sensitive information (CWE-319) over the network. The vulnerability is unauthenticated, meaning any network-adjacent attacker can capture credentials without requiring prior access to the system.
Business impact
The ability for an attacker to intercept administrative or user credentials poses a significant risk to the confidentiality and integrity of medical imaging data. Given the CVSS score of 7.4, this vulnerability represents a high risk that could lead to unauthorized access to the PACS environment, potentially resulting in data exfiltration or unauthorized manipulation of patient records.
Remediation
Immediate Action: Update the Sante PACS Server software to version 4.2.3 or later as specified in the vendor advisory.
Proactive Monitoring: Review network traffic logs for suspicious patterns and ensure that all web portal communications are forced over encrypted channels where possible.
Compensating Controls: Implement network segmentation to isolate the PACS server and utilize a Web Application Firewall or VPN to encrypt traffic if an immediate software update is operationally delayed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk of credential interception in a medical environment necessitates prompt action. Administrators should prioritize the upgrade to version 4.2.3 immediately to eliminate the cleartext transmission of credentials and secure the authentication process against network-based sniffing attacks.
Sources
Originally found and disclosed by Chizuru Toyama of TXOne Networks reported these vulnerabilities to CISA., per the CVE Program record.