CVE-2013-4425

UnknownEPSS 0.35%

Last modified

CVE-2013-4425 is a vulnerability of currently unknown severity. The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.

Metrics

EPSS Probability
0.35%

26.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Osirix-ViewerOsirix<= 5.7
Osirix-ViewerOsirix0.2
Osirix-ViewerOsirix1.0
Osirix-ViewerOsirix1.1
Osirix-ViewerOsirix1.1.2
Osirix-ViewerOsirix1.2
Osirix-ViewerOsirix1.3
Osirix-ViewerOsirix1.4
Osirix-ViewerOsirix1.5
Osirix-ViewerOsirix1.5.1
Osirix-ViewerOsirix1.5.2
Osirix-ViewerOsirix1.6
Osirix-ViewerOsirix1.6.2
Osirix-ViewerOsirix1.6.3
Osirix-ViewerOsirix1.6.4
Osirix-ViewerOsirix1.6.5
Osirix-ViewerOsirix1.7
Osirix-ViewerOsirix1.7.1
Osirix-ViewerOsirix2.0
Osirix-ViewerOsirix2.1
Osirix-ViewerOsirix2.2
Osirix-ViewerOsirix2.3
Osirix-ViewerOsirix2.3.1
Osirix-ViewerOsirix2.4
Osirix-ViewerOsirix2.5
Osirix-ViewerOsirix2.6
Osirix-ViewerOsirix2.7.5
Osirix-ViewerOsirix3.0
Osirix-ViewerOsirix3.1
Osirix-ViewerOsirix3.2.1
Osirix-ViewerOsirix3.3
Osirix-ViewerOsirix3.5
Osirix-ViewerOsirix3.6
Osirix-ViewerOsirix3.7.1
Osirix-ViewerOsirix3.8.1
Osirix-ViewerOsirix3.9.4
Osirix-ViewerOsirix4.0
Osirix-ViewerOsirix4.1.2
Osirix-ViewerOsirix5.0.2
Osirix-ViewerOsirix5.5.2
Osirix-ViewerOsirix5.6
Osirix-ViewerOsirix Md<= 2.7

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-4425?
The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.
How severe is CVE-2013-4425?
Severity scoring for CVE-2013-4425 is pending analysis. The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2013-4425?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-4425?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST