NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01 | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-12-02 21:15
Updated : 2026-01-02 21:02
NVD link : CVE-2025-64298
Mitre link : CVE-2025-64298
CVE.ORG link : CVE-2025-64298
JSON object : View
Products Affected
microsoft
- windows
mirion
- biodose\/nmis
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
