CVE-2025-14096
Unknown Unknown - Not Provided
Credential Extraction via Physical Access in Radiometer Analyzers

Publication date: 2025-12-17

Last updated on: 2025-12-17

Assigner: Radiometer

Description
A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possibility to extract credential information. The vulnerability is due to a weakness in the design and insufficient credential protection in operating system. Other related CVE's are CVE-2025-14095 & CVE-2025-14097. Affected customers have been informed about this vulnerability. This CVE is being published to provide transparency. Required Configuration for Exposure: Attacker requires physical access to the analyzer. Temporary work Around: Only authorized people can physically access the analyzer. Permanent solution: Local Radiometer representatives will contact all affected customers to discuss a permanent solution. Exploit Status: Researchers have provided a working proof-of-concept (PoC). Radiometer is not aware of any public exploit code at the time of this publication.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-17
Last Modified
2025-12-17
Generated
2026-05-07
AI Q&A
2025-12-17
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
radiometer analyzer *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in multiple Radiometer products and allows an attacker with physical access to the analyzer to extract credential information. It is caused by a weakness in the design and insufficient protection of credentials within the operating system.


How can this vulnerability impact me? :

If exploited, this vulnerability can lead to unauthorized access to sensitive credential information, potentially compromising the confidentiality, integrity, and availability of the system and its data. Since the attacker needs physical access, the risk is limited to scenarios where such access is possible.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability immediately, ensure that only authorized personnel have physical access to the Radiometer analyzer devices. Restricting physical access is the primary temporary workaround until a permanent solution is provided by local Radiometer representatives.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart