ET WEB_SPECIFIC_APPS MedDream PACS Premium cecho.php SSRF Attempt (CVE-2025-24485)

SID: 2069374Rev: 13 views
Sourceet/open
CreatedMay 20, 2026
UpdatedMay 20, 2026
Classificationattempted-admin
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS MedDream PACS Premium cecho.php SSRF Attempt (CVE-2025-24485)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/Pacs/cecho.php|3f|"; startswith; fast_pattern; content:"ipaddr|3d|"; content:"port|3d|"; reference:url,talosintelligence.com/vulnerability_reports/TALOS-2025-2177; reference:cve,2025-24485; classtype:attempted-admin; sid:2069374; rev:1; metadata:affected_product MedDream, attack_target Server, tls_state plaintext, created_at 2026_05_20, cve CVE_2025_24485, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Minor, tag Exploit, updated_at 2026_05_20, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1018, mitre_technique_name Remote_System_Discovery; target:dest_ip;)

Metadata

affected productMedDream
attack targetServer
tls stateplaintext
created at2026_05_20
deploymentInternal
performance impactLow
confidenceHigh
signature severityMinor
tagExploit
updated at2026_05_20
mitre tactic idTA0007
mitre tactic nameDiscovery
mitre technique idT1018
mitre technique nameRemote_System_Discovery

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!