INFINITT Healthcare’s Picture Archiving and Communication System (PACS) is affected by CVE-2025-27714 (unrestricted file upload, CVSS v4 8.7) and CVE-2025-27721 (unauthorized access, CVSS v4 8.7), which could enable attackers to execute malicious code or access patient data. These advisories aim to inform stakeholders about critical security issues, exploits, and mitigation strategies for ICS technologies widely deployed across essential sectors like manufacturing, energy, healthcare, and infrastructure. Exploitation could result in unauthorized access, data manipulation, denial-of-service conditions, or remote code execution—potentially disrupting essential services. Attackers could exploit improper input validation to inject malicious configurations, leading to arbitrary code execution or exposure of cluster-wide secrets. These flaws, with CVSS v4 scores up to 9.2, allow local attackers to escalate privileges or disclose sensitive data. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The vulnerabilities expose systems to potential code execution or information disclosure due to out-of-bounds writes (CWE-787) and stack-based buffer overflows (CWE-125). Exploits could allow local users to escalate privileges or execute arbitrary code. A path traversal vulnerability (CWE-22) in the web interface could enable unauthorized access to files with root privileges. Kaaviya is a Security Editor and fellow reporter with Cyber Security News.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 11 Apr 2025 14:50:17 +0000