PatchSiren cyber security CVE debrief
CVE-2025-27720 Pixmeo CVE debrief
CVE-2025-27720 is a high-severity issue in Pixmeo OsiriX MD where the Web Portal sends credential information without encryption. That creates a risk that credentials could be intercepted by an attacker who can observe the traffic path.
- Vendor
- Pixmeo
- Product
- OsiriX MD
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-08
- Original CVE updated
- 2025-05-08
- Advisory published
- 2025-05-08
- Advisory updated
- 2025-05-08
Who should care
Organizations using Pixmeo OsiriX MD, especially teams that administer or rely on the OsiriX MD Web Portal and any environment where portal traffic may traverse untrusted or shared networks.
Technical summary
CISA’s advisory states that the OsiriX MD Web Portal transmits credential information without encryption. In practice, that means credentials may be exposed to passive network interception, allowing an attacker to steal them if they can observe the traffic.
Defensive priority
High. The issue directly affects credential confidentiality and can enable account compromise if traffic is exposed. Because the advisory describes cleartext credential transmission, remediation should be prioritized for any deployment that uses the affected portal.
Recommended defensive actions
- Install the latest version of OsiriX MD as recommended by Pixmeo.
- If you need assistance or cannot confirm the updated version, contact Pixmeo directly using the vendor support channel.
- Review Web Portal access paths and restrict use to trusted networks until the updated version is in place.
- Treat any credentials used through the portal as potentially exposed if unencrypted transmission was observed, and rotate them where appropriate.
- Verify that portal traffic is protected by encryption and that no configuration, proxy, or deployment path reintroduces cleartext credential handling.
Evidence notes
Based on the supplied CISA CSAF advisory (ICSMA-25-128-01) for CVE-2025-27720, published 2025-05-08. The advisory description and notes state that the OsiriX MD Web Portal sends credential information without encryption and that an attacker could steal credentials. The remediation section directs users to download the latest version of OsiriX MD and to contact Pixmeo for support. The supplied data does not list a KEV entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-27720 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-27720
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-27720 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27720
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-128-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-128-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.