CVE-2025-64298
Last modified
CVE-2025-64298 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mirion | Biodose\/Nmis | < 23.0 |
References
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-64298?
How severe is CVE-2025-64298?
How do I fix CVE-2025-64298?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64291Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-64292Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-64293Improper Neutralization of Special Elements used in an SQL C…7.6
- CVE-2025-64294Missing Authorization vulnerability in d3wp WP Snow Effect w…5.3
- CVE-2025-64295Insertion of Sensitive Information Into Sent Data vulnerabil…6.5
- CVE-2025-64296Missing Authorization vulnerability in Facebook Facebook for…5.3
- CVE-2025-64299LogStare Collector improperly handles the password hash data…2.7
- CVE-2025-6430When a file download is specified via the `Content-Dispositi…6.1
- CVE-2025-64301An out‑of‑bounds write vulnerability exists in the EMF funct…7.8
- CVE-2025-64302Insufficient input sanitization in the dashboard label or pa…5.4
- CVE-2025-64304"FOD" App uses hard-coded cryptographic keys, which may allo…5.1
- CVE-2025-64305MicroServer copies parts of the system firmware to an unencr…7.1
Are you affected by CVE-2025-64298?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
