CVE-2025-27720

HIGH

Pixmeo Osirix MD Web Portal - Info Disclosure

Title source: llm
STIX 2.1

Description

The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.

Scores

CVSS v3 7.4
EPSS 0.0006
EPSS Percentile 19.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-319
Status published
Products (1)
Pixmeo/OsiriX MD < 14.0.1 (Build 2024-02-28)
Published May 08, 2025
Tracked Since Feb 18, 2026