---
id: CVE-2025-64642
title: >-
  NMIS/BioDose V22.02 and previous versions' installation directory paths by
  default have insecure file permissions, which in certain deployment scenarios
  can enable users on client workstations to modify the program executables and
  librar…
summary: >-
  NMIS/BioDose V22.02 and previous versions' installation directory paths by
  default have insecure file permissions, which in certain deployment scenarios
  can enable users on client workstations to modify the program executables and
  librar…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-732
vendor: mirion
product: biodose/nmis
affected:
  - biodose/nmis < 23.0
patched:
  - biodose/nmis 23.0
published: '2025-12-02'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64642'
references:
  - url: 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00118
epssPercentile: 0.01541
ingestedAt: '2026-09-25T23:21:16.867Z'
---

## Overview

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.

## Affected

- `biodose/nmis < 23.0`

## Remediation

Upgrade past the affected range:

- `biodose/nmis 23.0`
