← CVE Tracker
8.4HIGH

CVE-2025-64298 — NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is…

Mirion · Biodose/Nmis · Published 2 Dec 2025 · Modified 25 Sept 2026

Description

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.

References

What to do
  1. Check whether Biodose/Nmis is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-64298