First published: Thu May 08 2025(Updated: )
The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Osirix MD |
Pixmeo recommends users to download the latest version of OsiriX MD https://www.osirix-viewer.com/osirix/osirix-md/ . For additional support regarding OsiriX MD, users should contact Pixmeo https://www.osirix-viewer.com/about/contact/ directly.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27720 is considered a critical vulnerability due to the potential for credential theft.
To fix CVE-2025-27720, implement encryption for credential information being transmitted by the Osirix MD Web Portal.
The primary impact of CVE-2025-27720 is the unauthorized access to user credentials, leading to possible data breaches.
As of now, there are no confirmed reports of active exploitation of CVE-2025-27720, but the risk remains high.
CVE-2025-27720 affects users of the Pixmeo Osirix MD Web Portal who send credentials without encryption.