PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-54759 Santesoft CVE debrief

CVE-2025-54759 affects Santesoft Sante PACS Server and is described as a stored cross-site scripting issue. CISA’s advisory says a malicious actor could inject HTML that redirects a user to a harmful webpage and may steal the user’s cookie. Santesoft’s remediation is to update PACS Server to Version 4.2.3 or later.

Vendor
Santesoft
Product
Sante PACS Server
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2025-08-12
Advisory published
2025-08-12
Advisory updated
2025-08-12

Who should care

Organizations running Santesoft Sante PACS Server, especially administrators and users in medical imaging environments, should review and apply the vendor update.

Technical summary

The supplied CISA CSAF advisory identifies a stored cross-site scripting vulnerability in Santesoft Sante PACS Server. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which indicates a network-reachable issue that requires user interaction and can affect confidentiality and integrity at a low level. CISA’s description states that injected malicious HTML can redirect a user to a malicious webpage and steal cookies. The advisory’s remediation is to update to PACS Server Version 4.2.3 or later.

Defensive priority

Medium. Treat as a priority patch for affected deployments, with faster action if the server is internet-facing or used by many internal users.

Recommended defensive actions

  • Upgrade Sante PACS Server to Version 4.2.3 or later as recommended by Santesoft.
  • Review any pages or fields that accept user-supplied content for stored XSS exposure and verify input/output handling.
  • Clear session cookies and review authentication/session controls after remediation if abuse is suspected.
  • Use browser and application hardening controls that reduce cookie theft impact, such as secure session handling and least-privilege access.
  • Monitor for suspicious redirects, unexpected HTML content, or user reports of unusual browser behavior in the PACS interface.

Evidence notes

All statements are taken from the supplied CISA CSAF advisory metadata and remediation entry for CVE-2025-54759. The advisory was published and last modified on 2025-08-12T06:00:00.000Z. The source corpus does not mark this CVE as KEV, and no ransomware-campaign linkage is provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-54759 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-54759

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-54759 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-54759

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-224-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-224-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.