PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64778 Mirion Medical CVE debrief

Mirion Medical’s NMIS/BioDose software is affected by hard-coded plain-text passwords in executable binaries. CISA’s advisory says versions V22.02 and earlier may allow unauthorized access to both the application and the database, and rates the issue as High severity.

Vendor
Mirion Medical
Product
EC2 Software NMIS BioDose
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-02
Original CVE updated
2026-09-25
Advisory published
2025-12-02
Advisory updated
2026-09-25

Who should care

Administrators and operators running Mirion Medical EC2 Software NMIS/BioDose, especially installations on V22.02 or any earlier version, should prioritize this issue.

Technical summary

The CISA CSAF advisory for CVE-2025-64778 states that NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain-text hard-coded passwords. The stated impact is potential unauthorized access to the application and database. The supplied CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) indicates the issue is locally reachable and can affect confidentiality and integrity significantly.

Defensive priority

High for any affected installation. Upgrade planning should be immediate because the vendor states that V23.0 or later resolves the issue.

Recommended defensive actions

  • Update NMIS/BioDose to V23.0 or later as recommended by Mirion Medical.
  • If you have an active support contract, use the vendor’s update path or contact Mirion Medical support directly.
  • Identify all installations running V22.02 or earlier and confirm exposure scope.
  • Review application and database access logs for unexpected authentication activity on affected systems.
  • After upgrading, verify credential handling and rotate any credentials that may have been exposed or reused in affected deployments.

Evidence notes

CISA’s official CSAF advisory (ICSMA-25-336-01) published on 2025-12-02 states that NMIS/BioDose V22.02 and previous versions contain executable binaries with plain-text hard-coded passwords. The advisory says these passwords could allow unauthorized access to both the application and database. The supplied remediation is to update to V23.0 or later. No KEV listing is present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64778 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64778

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64778 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64778

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-336-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.