PatchSiren cyber security CVE debrief
CVE-2025-54808 Oxford Nanopore Technologies CVE debrief
CVE-2025-54808 affects Oxford Nanopore Technologies MinKNOW version 24.11 and earlier. The advisory says MinKNOW stores authentication tokens in a file under the system temporary directory (/tmp), which is typically world-readable on the host. That can let another local user or application read the token. If the token is exposed and Remote Connect is enabled, an attacker can use it to establish unauthorized remote connections to the sequencer. The advisory also notes that this access can be chained to create developer tokens with arbitrary expiration dates, which can support persistent access. This is a local-to-remote risk: the initial exposure depends on local access or local malware, and remote abuse depends on Remote Connect being enabled. CISA published the issue as ICSMA-25-294-01 on 2025-10-21 with a CVSS 3.1 score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vendor
- Oxford Nanopore Technologies
- Product
- MinKNOW
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-10-21
- Original CVE updated
- 2025-10-21
- Advisory published
- 2025-10-21
- Advisory updated
- 2025-10-21
Who should care
Operators of MinKNOW-based sequencing systems, lab IT administrators, OT/ICS security teams, and endpoint defenders responsible for hosts running MinKNOW 24.11 or earlier—especially where multiple local users exist or Remote Connect is enabled.
Technical summary
CISA’s CSAF advisory states that MinKNOW at or prior to version 24.11 stores authentication tokens in /tmp on the host machine. Because /tmp is typically world-readable, local users or applications may be able to access the token. Successful remote misuse requires Remote Connect to be enabled; the advisory notes this may be enabled intentionally for operations or by malware with elevated privileges. The source rates the issue CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Defensive priority
High. Upgrade affected systems as soon as possible, and treat any MinKNOW 24.11-or-earlier host with Remote Connect enabled as urgent to review.
Recommended defensive actions
- Upgrade to MinKNOW versions later than 24.11.
- Keep Remote Connect disabled unless it is strictly required, and enable it only within trusted network environments.
- Install and maintain antivirus and malware-scanning tools on affected hosts.
- If you cannot upgrade immediately, contact Oxford Nanopore Support for configuration guidance.
- Review MinKNOW hosts for unnecessary local access exposure and investigate any unexpected Remote Connect use or token handling issues.
Evidence notes
The supplied CISA CSAF advisory (ICSMA-25-294-01) and source record were initially published on 2025-10-21, with the same modified date in the provided timeline. The advisory says MinKNOW at or prior to 24.11 stores authentication tokens in /tmp, that /tmp is typically world-readable, that remote misuse requires Remote Connect to be enabled, and that developer tokens can be created with arbitrary expiration dates. The provided CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-54808 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-54808
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-54808 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-54808
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-294-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-294-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.