CVE-2013-4425: Osirix-Viewer Osirix
Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.
Affected products
- Osirix-Viewer Osirix: up to and including 5.7; version 0.2 only; version 1.0 only; version 1.1 only; version 1.1.2 only; version 1.2 only; …
- Osirix-Viewer Osirix Md: up to and including 2.7
Published 2013-11-18. Last modified 2026-06-16.