---
id: CVE-2025-64298
title: >-
  NMIS/BioDose V22.02 and previous version installations where the embedded
  Microsoft SQLServer Express is used are exposed in the Windows share accessed
  by clients in networked installs
summary: >-
  NMIS/BioDose V22.02 and previous version installations where the embedded
  Microsoft SQLServer Express is used are exposed in the Windows share accessed
  by clients in networked installs. By default, this directory has insecure
  directory p…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-732
vendor: mirion
product: biodose/nmis
affected:
  - biodose/nmis < 23.0
patched:
  - biodose/nmis 23.0
published: '2025-12-02'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64298'
references:
  - url: 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00234
epssPercentile: 0.12917
ingestedAt: '2026-09-25T23:21:16.867Z'
---

## Overview

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.

## Affected

- `biodose/nmis < 23.0`

## Remediation

Upgrade past the affected range:

- `biodose/nmis 23.0`
