8.6
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.
AI Analysis
Insecure directory paths in NMIS/BioDose allow access to sensitive SQL Server database and configuration files.
Basic Information
ID
CVE-2025-64298
Source
icscert
Published
Dec 2, 2025 at 21:05
Modified
Dec 2, 2025 at 21:40
Affected Product
Vendor
Mirion Medical
Product
EC2 Software NMIS BioDose
Affected Versions
Mirion Medical EC2 Software NMIS BioDose 0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Mirion Medical
Product
NMIS BioDose
Version
V22.02 and prior