Description
Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of HTTP Content-Length header. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26770.
Published: 2025-12-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Santesoft
Santesoft sante Pacs Server
Vendors & Products Santesoft
Santesoft sante Pacs Server

Tue, 23 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HTTP Content-Length header. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26770.
Title Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability
Weaknesses CWE-476
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Santesoft Sante Pacs Server
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2025-12-29T18:04:50.177Z

Reserved: 2025-12-10T20:41:55.862Z

Link: CVE-2025-14501

cve-icon Vulnrichment

Updated: 2025-12-29T18:04:47.309Z

cve-icon NVD

Status : Deferred

Published: 2025-12-23T22:15:51.533

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-24T11:51:34Z

Weaknesses