CVE-2025-27580: High severity nih brics vulnerability
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27580?
The severity of CVE-2025-27580 is critical due to the potential for privilege escalation and unauthorized access.
How do I fix CVE-2025-27580?
To fix CVE-2025-27580, update NIH BRICS to version 14.0.0-68 or later, which addresses the predictable token generation issue.
Who is affected by CVE-2025-27580?
Users of NIH BRICS versions up to and including 14.0.0-67 are affected by CVE-2025-27580.
What type of vulnerability is CVE-2025-27580?
CVE-2025-27580 is a privilege escalation vulnerability caused by predictable token generation.
Can CVE-2025-27580 be exploited remotely?
Yes, CVE-2025-27580 can be exploited by unauthenticated users with a Common Access Card (CAC) to compromise accounts.