PT-2025-43538 · Oxford Nano Technologies · Minknow
Published
2025-10-23
·
Updated
2025-10-23
·
CVE-2025-10937
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Oxford Nanopore Technologies MinKNOW versions prior to 24.11
Description
The MinKNOW software creates a temporary file to store the local authentication token during startup, before moving it to its final location. This temporary file is created in a directory accessible to all users on the system. An unauthorized local user or process can exploit this by placing a file lock on the temporary token file using the
flock system call. This prevents MinKNOW from completing the token generation process, resulting in no valid local token being created. Consequently, the software cannot execute commands on the sequencer, leading to a denial-of-service (DoS) condition that blocks sequencing operations.Recommendations
Update MinKNOW to version 24.11 or later.
Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minknow