216.73.217.22

CVE-2025-26469

· Published 28/07/2025 14:15 · Modified 29/07/2025 14:14

Labels: CVE-2025-26469 2025-07-28CVE-2025-26469CWE-732[email protected]

Essential information

Published
28/07/2025 14:15
Modified
29/07/2025 14:14
Author
Creator
CVSS
9.3 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application can decrypt credentials stored in a configuration-related registry key. An attacker can execute a malicious script or application to exploit this vulnerability.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
meddream / pac premium cpe:2.3:a:meddream:pac_premium:7.3.3.840:*:*:*:*:*:*:*

References