CVE-2025-53948: Santesoft Sante Pacs Server

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.

Affected products

  • Santesoft Sante Pacs Server: before 4.2.3 (fixed in 4.2.3)

Published 2025-08-18. Last modified 2026-06-17.