CVE-2025-64778
7.3Mirion Medical · EC2 Software NMIS BioDose
Mirion Medical NMIS/BioDose software contains hard-coded passwords in executable binaries, potentially allowing unauthorized access to the application and database.
Executive summary
The presence of hard-coded credentials in Mirion Medical NMIS/BioDose software creates a high-risk security vulnerability that could allow unauthorized access to sensitive application and database components.
Vulnerability
This vulnerability involves the use of hard-coded credentials (CWE-798) within executable binaries. While the attack vector requires local access (AV:L) and low privileges (PR:L), the flaw permits an attacker to bypass authentication mechanisms to gain unauthorized control over the application and its underlying database.
Business impact
The exploitation of this vulnerability poses a significant risk to data integrity and system confidentiality. Unauthorized access to the BioDose database could result in the compromise of sensitive medical information, operational disruption, and potential regulatory non-compliance. With a CVSS score of 7.3, this flaw is categorized as High severity, necessitating prompt remediation to prevent potential misuse of the hard-coded credentials.
Remediation
Immediate Action: Update the Mirion Medical EC2 Software NMIS BioDose installation to version 23.0 or later as recommended by the vendor.
Proactive Monitoring: Audit system logs for unexpected administrative logins or unauthorized queries originating from local user accounts that should not typically access the database configuration files.
Compensating Controls: Restrict local access to the server hosting the software to only authorized personnel and implement strict file system permissions to prevent unauthorized reading of the vulnerable binary files.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the High severity of this vulnerability, administrators should prioritize the upgrade to version 23.0 immediately. Hard-coded credentials provide a trivial pathway for attackers to escalate privileges or exfiltrate data, and patching remains the only reliable method to eliminate this risk. Ensure all systems are brought to the current version to maintain the security and integrity of medical data operations.
Sources
Originally found and disclosed by Joe Dillon reported these vulnerabilities to Mirion Medical., per the CVE Program record.