cbcvebase.

Mirion Medical Ec2 Software Nmis Biodose vulnerabilities

5 known vulnerabilities affecting mirion_medical/ec2_software_nmis_biodose.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5

Vulnerabilities

Page 1 of 1
CVE-2025-61940P2HIGHCVSS 8.8fixed in 23.02025-12-02
CVE-2025-61940 [HIGH] CWE-603 CVE-2025-61940: NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows
nvd
CVE-2025-62575P2HIGHCVSS 8.8fixed in 23.02025-12-02
CVE-2025-62575 [HIGH] CWE-732 CVE-2025-62575: NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user acco NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.
nvd
CVE-2025-64298P3HIGHCVSS 7.5fixed in 23.02025-12-02
CVE-2025-64298 [HIGH] CWE-732 CVE-2025-64298: NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Expres NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.
nvd
CVE-2025-64778P3HIGHCVSS 7.8fixed in 23.02025-12-02
CVE-2025-64778 [HIGH] CWE-798 CVE-2025-64778: NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard- NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.
nvd
CVE-2025-64642P3HIGHCVSS 7.8fixed in 23.02025-12-02
CVE-2025-64642 [HIGH] CWE-732 CVE-2025-64642: NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure fil NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.
nvd
Mirion Medical Ec2 Software Nmis Biodose vulnerabilities | cvebase