NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 23 Apr 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators. | |
Weaknesses | CWE-335 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-23T00:00:00.000Z
Updated: 2025-04-24T14:56:11.185Z
Reserved: 2025-03-03T00:00:00.000Z
Link: CVE-2025-27580

Updated: 2025-04-24T14:56:07.722Z

Status : Awaiting Analysis
Published: 2025-04-24T00:15:16.270
Modified: 2025-04-29T13:52:47.470
Link: CVE-2025-27580

No data.