---
id: CVE-2025-10937
title: >-
  Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11
  creates a temporary file to store the local authentication token during
  startup, before copying it to its final location
summary: >-
  Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11
  creates a temporary file to store the local authentication token during
  startup, before copying it to its final location. This temporary file is
  created in a dir…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-754
published: '2025-10-23'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10937'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsma-25-294-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://nanoporetech.com/about/contact'
    label: ics-cert@hq.dhs.gov
  - url: 'https://nanoporetech.com/software/'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-294-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00159
epssPercentile: 0.04486
ingestedAt: '2026-10-08T11:31:27.560Z'
---

## Overview

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local authentication token during startup, before copying it to its final location. This temporary file is created in a directory accessible to all users on the system. An unauthorized local user or process can exploit this behavior by placing a file lock on the temporary token file using the flock system call. This prevents MinKNOW from completing the token generation process. As a result, no valid local token is created, and the software is unable to execute commands on the sequencer. This leads to a denial-of-service (DoS) condition, blocking sequencing operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
