CVE-2025-53948

Severity CVSS v4.0:
HIGH
Type:
CWE-415 Double Free
Publication date:
18/08/2025
Last modified:
17/10/2025

Description

The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:santesoft:sante_pacs_server:*:*:*:*:*:*:*:* 4.2.3 (excluding)