PoC Index

CVE-2025-2264

HIGH 7.5EPSS 34.5%

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
34.55% chance of exploitation in the next 30 days, 98th percentile
Nuclei
high · CWE-22
Published
2025-03-13
Updated
2025-03-14

Proof-of-concept exploits (1)

Nuclei templates (1)

Metasploit modules (1)

References

Related