CVE-2025-0896

Source
https://cve.org/CVERecord?id=CVE-2025-0896
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0896.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-0896
Downstream
Published
2025-02-13T02:15:29.470Z
Modified
2026-03-12T17:32:02.259884Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0896.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "1.5.8"
            }
        ]
    }
]