We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based buffer is passed to the function as the output buffer. A stack-based buffer overflow exists if a long encrypted username or password is supplied by an unauthenticated remote attacker.
Reserved 2025-03-12 | Published 2025-03-13 | Updated 2025-03-14 | Assigner tenableCWE-121: Stack-based Buffer Overflow
www.tenable.com/security/research/tra-2025-08
Support options