Back to Database
Status published
Critical
CVE-2025-54156
Santesoft Sante PACS Server Cleartext Transmission of Sensitive Information
Vulnerability Description
The Sante PACS Server Web Portal sends credential information without encryption.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54156
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Chizuru Toyama of TXOne Networks reported these vulnerabilities to CISA.
More from Santesoft
View All →CVE-2025-5307
Santesoft Sante DICOM Viewer Pro Out-of-bounds Read
High
8.4
CVE-2025-54862
Santesoft Sante PACS Server Cross-site Scripting
Medium
4.8
CVE-2025-54759
Santesoft Sante PACS Server Cross-site Scripting
Medium
5.1
CVE-2025-53948
Santesoft Sante PACS Server Double Free
High
8.7
CVE-2025-2480
Santesoft Sante DICOM Viewer Pro Out-of-bounds Write
High
8.4
Affected Vendor
Santesoft
View all reports →Affected Software
Sante PACS Server
Vulnerable Versions:
0
Timeline
Official Publish:
August 18th, 2025
Last Modified:
August 19th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H