Aller au contenu

Fiche vulnérabilité

CVE-2025-64298 : faille élevée mirion biodose\/nmis (CVSS 7.5)

Description

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
2 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • mirion biodose\/nmis

Références

Rechercher une autre vulnérabilité dans la base CVE