Skip to main content
EPSS 0.2%top 95%

CVE-2025-54808: CWE-522 Insufficiently Protected Credentials in Oxford Nanopore Technologies MinKNOW

0
High
VulnerabilityCVE-2025-54808cvecve-2025-54808cwe-522
Published: 10/23/2025 (10/23/2025, 18:21:19 UTC)
Source: CVE Database V5
Vendor/Project: Oxford Nanopore Technologies
Product: MinKNOW

Description

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the token is leaked (e.g., via malware infection or other local exploit), and remote access is enabled, it can be used to establish unauthorized remote connections to the sequencer. Remote access must be enabled for remote exploitation to succeed. This may occur either because the user has enabled remote access for legitimate operational reasons or because malware with elevated privileges (e.g., sudo access) enables it without user consent. This vulnerability can be chained with remote access capabilities to generate a developer token from a remote device. Developer tokens can be created with arbitrary expiration dates, enabling persistent access to the sequencer and bypassing standard authentication mechanisms.

CVSS v4.0

Score 7.3high

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Affected versions
=0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/05/2026, 20:28:34 UTC

Technical Analysis

MinKNOW software versions at or prior to 24.11 store authentication tokens in the system's /tmp directory, which is typically world-readable. This insecure storage allows local users or applications to access these tokens. If remote access is enabled, an attacker with access to the token can remotely connect to the sequencer. The vulnerability can be chained to generate developer tokens with arbitrary expiration dates, allowing persistent access and bypassing normal authentication. Exploitation requires local access to the host system and remote access enabled on the sequencer. The vulnerability is identified as CWE-522 and has a CVSS 4.0 score of 7.3, indicating high severity. There is no information about an available patch or vendor advisory specifying remediation.

Potential Impact

Unauthorized local users or applications can access authentication tokens stored insecurely in a world-readable temporary directory. If remote access is enabled, these tokens can be used to establish unauthorized remote connections to the sequencer. Attackers can generate developer tokens with arbitrary expiration dates, enabling persistent unauthorized access and bypassing standard authentication controls. This could lead to compromise of the sequencer's operation and data integrity. Exploitation requires local access and remote access enabled, limiting the attack vector to environments where these conditions are met.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to restrict local access to the host system to trusted users only and disable remote access on the sequencer if not required. Monitor for unauthorized enabling of remote access and consider securing the /tmp directory or the token storage mechanism to prevent unauthorized local access. Follow any updates from Oxford Nanopore Technologies regarding patches or configuration changes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
icscert
Date Reserved
2025-09-23T19:54:22.511Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68fa73f6bf11aeb6491dbf97

Added to database: 10/23/2025, 18:29:10 UTC

Last enriched: 06/05/2026, 20:28:34 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 341

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses