CVE-2025-14096 describes a high-severity vulnerability in multiple Radiometer products, allowing an attacker with physical access to extract credential information due to insufficient protection in the operating system. The CVSS score of 8.4 (HIGH) indicates a local attack vector with low complexity, leading to high impact on confidentiality, integrity, and availability. While a proof-of-concept exists, Radiometer is not aware of public exploit code, and there is currently no community discussion or media coverage. Affected customers have been informed, and a permanent solution is being developed, with a temporary workaround of restricting physical access to authorized personnel.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Radiometer Medical Aps | ABL800 BASIC And ABL800 FLEX Analyzers | Windows 7 Operating system, Windows XP Operating systemCNA affecteddefault unaffected | |
| Radiometer Medical Aps | ABL90 FLEX And ABL90 FLEX PLUS Analyzers | Windows 7 Operating system, Windows XP Operating systemCNA affecteddefault unaffected | |
| Radiometer Medical Aps | AQT90 FLEX Analyzers | Windows 7 Operating system, Windows XP Operating systemCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.