CVE-2013-4425: Osirix-Viewer Osirix

Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.

Affected products

  • Osirix-Viewer Osirix: up to and including 5.7; version 0.2 only; version 1.0 only; version 1.1 only; version 1.1.2 only; version 1.2 only; …
  • Osirix-Viewer Osirix Md: up to and including 2.7

Published 2013-11-18. Last modified 2026-06-16.