PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-27720 Pixmeo CVE debrief

CVE-2025-27720 is a high-severity issue in Pixmeo OsiriX MD where the Web Portal sends credential information without encryption. That creates a risk that credentials could be intercepted by an attacker who can observe the traffic path.

Vendor
Pixmeo
Product
OsiriX MD
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2025-05-08
Original CVE updated
2025-05-08
Advisory published
2025-05-08
Advisory updated
2025-05-08

Who should care

Organizations using Pixmeo OsiriX MD, especially teams that administer or rely on the OsiriX MD Web Portal and any environment where portal traffic may traverse untrusted or shared networks.

Technical summary

CISA’s advisory states that the OsiriX MD Web Portal transmits credential information without encryption. In practice, that means credentials may be exposed to passive network interception, allowing an attacker to steal them if they can observe the traffic.

Defensive priority

High. The issue directly affects credential confidentiality and can enable account compromise if traffic is exposed. Because the advisory describes cleartext credential transmission, remediation should be prioritized for any deployment that uses the affected portal.

Recommended defensive actions

  • Install the latest version of OsiriX MD as recommended by Pixmeo.
  • If you need assistance or cannot confirm the updated version, contact Pixmeo directly using the vendor support channel.
  • Review Web Portal access paths and restrict use to trusted networks until the updated version is in place.
  • Treat any credentials used through the portal as potentially exposed if unencrypted transmission was observed, and rotate them where appropriate.
  • Verify that portal traffic is protected by encryption and that no configuration, proxy, or deployment path reintroduces cleartext credential handling.

Evidence notes

Based on the supplied CISA CSAF advisory (ICSMA-25-128-01) for CVE-2025-27720, published 2025-05-08. The advisory description and notes state that the OsiriX MD Web Portal sends credential information without encryption and that an attacker could steal credentials. The remediation section directs users to download the latest version of OsiriX MD and to contact Pixmeo for support. The supplied data does not list a KEV entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-27720 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-27720

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-27720 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27720

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-128-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-128-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.