CVE-2025-64298

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mirion:biodose\/nmis:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

02 Jan 2026, 21:02

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:mirion:biodose\/nmis:*:*:*:*:*:*:*:*
First Time Mirion
Microsoft windows
Microsoft
Mirion biodose\/nmis
References () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01 - () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01 - Third Party Advisory

02 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 21:15

Updated : 2026-01-02 21:02


NVD link : CVE-2025-64298

Mitre link : CVE-2025-64298

CVE.ORG link : CVE-2025-64298


JSON object : View

Products Affected

mirion

  • biodose\/nmis

microsoft

  • windows
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource