CVE-2025-64642

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mirion:biodose\/nmis:*:*:*:*:*:*:*:*

History

02 Jan 2026, 20:59

Type Values Removed Values Added
CPE cpe:2.3:a:mirion:biodose\/nmis:*:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01 - () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01 - Third Party Advisory
First Time Mirion
Mirion biodose\/nmis

02 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 21:15

Updated : 2026-01-02 20:59


NVD link : CVE-2025-64642

Mitre link : CVE-2025-64642

CVE.ORG link : CVE-2025-64642


JSON object : View

Products Affected

mirion

  • biodose\/nmis
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource