CVE-2025-64298
8.4Mirion Medical · EC2 Software NMIS BioDose
Mirion Medical NMIS/BioDose V22 and earlier versions utilize insecure directory permissions for embedded SQL Server files, allowing unauthorized access to sensitive database and configuration data.
Executive summary
A critical vulnerability in Mirion Medical NMIS/BioDose exposes sensitive database and configuration files due to insecure directory permissions, risking total loss of data confidentiality and integrity.
Vulnerability
The software suffers from incorrect permission assignment (CWE-732) for critical resources, where the directory hosting the embedded Microsoft SQL Server Express is accessible to unauthorized users on the network. This allows local or network-based actors to retrieve sensitive configuration data and database contents without requiring specialized authentication.
Business impact
The exposure of the backend database and configuration files presents a severe risk to clinical data security and patient privacy. With a CVSS score of 8.4, this vulnerability enables attackers to extract sensitive information, potentially leading to unauthorized data modification or total system compromise, which could result in regulatory non-compliance and clinical operational disruption.
Remediation
Immediate Action: Upgrade to Mirion Medical EC2 Software NMIS BioDose version 23.0 or later, which addresses the insecure permission configuration.
Proactive Monitoring: Review Windows file share access logs for unusual patterns or unauthorized attempts to access the directory paths associated with the SQL Server installation.
Compensating Controls: Restrict network access to the affected file shares using host-based firewalls or network access control lists to ensure only authorized service accounts can reach the database directory.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from IT and security teams. Administrators should prioritize the upgrade to version 23.0 to remediate the insecure permission structure, as relying on network segmentation alone may not be sufficient to protect sensitive clinical data if the internal network is breached.
Sources
Originally found and disclosed by Joe Dillon reported these vulnerabilities to Mirion Medical., per the CVE Program record.