CVE-2025-54808: CWE-522 Insufficiently Protected Credentials in Oxford Nanopore Technologies MinKNOW
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the token is leaked (e.g., via malware infection or other local exploit), and remote access is enabled, it can be used to establish unauthorized remote connections to the sequencer. Remote access must be enabled for remote exploitation to succeed. This may occur either because the user has enabled remote access for legitimate operational reasons or because malware with elevated privileges (e.g., sudo access) enables it without user consent. This vulnerability can be chained with remote access capabilities to generate a developer token from a remote device. Developer tokens can be created with arbitrary expiration dates, enabling persistent access to the sequencer and bypassing standard authentication mechanisms.
AI Analysis
Technical Summary
MinKNOW software versions at or prior to 24.11 store authentication tokens in the system's /tmp directory, which is typically world-readable. This insecure storage allows local users or applications to access these tokens. If remote access is enabled, an attacker with access to the token can remotely connect to the sequencer. The vulnerability can be chained to generate developer tokens with arbitrary expiration dates, allowing persistent access and bypassing normal authentication. Exploitation requires local access to the host system and remote access enabled on the sequencer. The vulnerability is identified as CWE-522 and has a CVSS 4.0 score of 7.3, indicating high severity. There is no information about an available patch or vendor advisory specifying remediation.
Potential Impact
Unauthorized local users or applications can access authentication tokens stored insecurely in a world-readable temporary directory. If remote access is enabled, these tokens can be used to establish unauthorized remote connections to the sequencer. Attackers can generate developer tokens with arbitrary expiration dates, enabling persistent unauthorized access and bypassing standard authentication controls. This could lead to compromise of the sequencer's operation and data integrity. Exploitation requires local access and remote access enabled, limiting the attack vector to environments where these conditions are met.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to restrict local access to the host system to trusted users only and disable remote access on the sequencer if not required. Monitor for unauthorized enabling of remote access and consider securing the /tmp directory or the token storage mechanism to prevent unauthorized local access. Follow any updates from Oxford Nanopore Technologies regarding patches or configuration changes.
CVE-2025-54808: CWE-522 Insufficiently Protected Credentials in Oxford Nanopore Technologies MinKNOW
Description
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the token is leaked (e.g., via malware infection or other local exploit), and remote access is enabled, it can be used to establish unauthorized remote connections to the sequencer. Remote access must be enabled for remote exploitation to succeed. This may occur either because the user has enabled remote access for legitimate operational reasons or because malware with elevated privileges (e.g., sudo access) enables it without user consent. This vulnerability can be chained with remote access capabilities to generate a developer token from a remote device. Developer tokens can be created with arbitrary expiration dates, enabling persistent access to the sequencer and bypassing standard authentication mechanisms.
CVSS v4.0
Score 7.3high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MinKNOW software versions at or prior to 24.11 store authentication tokens in the system's /tmp directory, which is typically world-readable. This insecure storage allows local users or applications to access these tokens. If remote access is enabled, an attacker with access to the token can remotely connect to the sequencer. The vulnerability can be chained to generate developer tokens with arbitrary expiration dates, allowing persistent access and bypassing normal authentication. Exploitation requires local access to the host system and remote access enabled on the sequencer. The vulnerability is identified as CWE-522 and has a CVSS 4.0 score of 7.3, indicating high severity. There is no information about an available patch or vendor advisory specifying remediation.
Potential Impact
Unauthorized local users or applications can access authentication tokens stored insecurely in a world-readable temporary directory. If remote access is enabled, these tokens can be used to establish unauthorized remote connections to the sequencer. Attackers can generate developer tokens with arbitrary expiration dates, enabling persistent unauthorized access and bypassing standard authentication controls. This could lead to compromise of the sequencer's operation and data integrity. Exploitation requires local access and remote access enabled, limiting the attack vector to environments where these conditions are met.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to restrict local access to the host system to trusted users only and disable remote access on the sequencer if not required. Monitor for unauthorized enabling of remote access and consider securing the /tmp directory or the token storage mechanism to prevent unauthorized local access. Follow any updates from Oxford Nanopore Technologies regarding patches or configuration changes.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- icscert
- Date Reserved
- 2025-09-23T19:54:22.511Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68fa73f6bf11aeb6491dbf97
Added to database: 10/23/2025, 18:29:10 UTC
Last enriched: 06/05/2026, 20:28:34 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 341
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.