Back to Database
Status published
Critical
CVE-2025-27720
Pixmeo OsiriX MD Cleartext Transmission of Sensitive Information
Vulnerability Description
The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27720
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Chizuru Toyama of TXOne Networks and Canaan Kao of TXOne Networks reported these vulnerabilities to CISA.
References
Affected Vendor
Pixmeo
View all reports →Affected Software
OsiriX MD
Vulnerable Versions:
0
Timeline
Official Publish:
May 8th, 2025
Last Modified:
May 9th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N