{"schema_version":1,"title":"Mirion Biodose\\ vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in Mirion Biodose\\: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-64778, was published on 2 December 2025.","url":"https://junglewise.ai/threats/technologies/biodose","json_url":"https://junglewise.ai/threats/technologies/biodose.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/biodose","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":5,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":5},"latest":[{"cve":"CVE-2025-64778","cvss":7.3,"epss":0.0012,"slug":"cve-2025-64778-nmis-biodose-software-v22-02-and-previous-versions-contain","title":"NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwo","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.75+00:00","url":"https://junglewise.ai/threats/cve-2025-64778-nmis-biodose-software-v22-02-and-previous-versions-contain"},{"cve":"CVE-2025-64642","cvss":8,"epss":0.0012,"slug":"cve-2025-64642-nmis-biodose-v22-02-and-previous-versions-installation-directory","title":"NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployme","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.557+00:00","url":"https://junglewise.ai/threats/cve-2025-64642-nmis-biodose-v22-02-and-previous-versions-installation-directory"},{"cve":"CVE-2025-64298","cvss":8.4,"epss":0.0023,"slug":"cve-2025-64298-nmis-biodose-v22-02-and-previous-version-installations-where-the","title":"NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows sha","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.333+00:00","url":"https://junglewise.ai/threats/cve-2025-64298-nmis-biodose-v22-02-and-previous-version-installations-where-the"},{"cve":"CVE-2025-62575","cvss":8.3,"epss":0.0042,"slug":"cve-2025-62575-nmis-biodose-v22-02-and-previous-versions-rely-on-a-microsoft-sql","title":"NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created account","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.133+00:00","url":"https://junglewise.ai/threats/cve-2025-62575-nmis-biodose-v22-02-and-previous-versions-rely-on-a-microsoft-sql"},{"cve":"CVE-2025-61940","cvss":8.3,"epss":0.0032,"slug":"cve-2025-61940-nmis-biodose-v22-02-and-previous-versions-rely-on-a-common-sql","title":"NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:51.93+00:00","url":"https://junglewise.ai/threats/cve-2025-61940-nmis-biodose-v22-02-and-previous-versions-rely-on-a-common-sql"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Mirion Nmis","slug":"nmis","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/nmis"}],"technology":{"hub":true,"name":"Mirion Biodose\\","slug":"biodose","vendor":{"name":"Mirion","slug":"mirion","url":"https://junglewise.ai/threats/vendors/mirion"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/biodose"},"most_severe":[{"cve":"CVE-2025-64298","cvss":8.4,"epss":0.0023,"slug":"cve-2025-64298-nmis-biodose-v22-02-and-previous-version-installations-where-the","title":"NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows sha","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.333+00:00","url":"https://junglewise.ai/threats/cve-2025-64298-nmis-biodose-v22-02-and-previous-version-installations-where-the"},{"cve":"CVE-2025-62575","cvss":8.3,"epss":0.0042,"slug":"cve-2025-62575-nmis-biodose-v22-02-and-previous-versions-rely-on-a-microsoft-sql","title":"NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created account","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.133+00:00","url":"https://junglewise.ai/threats/cve-2025-62575-nmis-biodose-v22-02-and-previous-versions-rely-on-a-microsoft-sql"},{"cve":"CVE-2025-61940","cvss":8.3,"epss":0.0032,"slug":"cve-2025-61940-nmis-biodose-v22-02-and-previous-versions-rely-on-a-common-sql","title":"NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:51.93+00:00","url":"https://junglewise.ai/threats/cve-2025-61940-nmis-biodose-v22-02-and-previous-versions-rely-on-a-common-sql"},{"cve":"CVE-2025-64642","cvss":8,"epss":0.0012,"slug":"cve-2025-64642-nmis-biodose-v22-02-and-previous-versions-installation-directory","title":"NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployme","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.557+00:00","url":"https://junglewise.ai/threats/cve-2025-64642-nmis-biodose-v22-02-and-previous-versions-installation-directory"},{"cve":"CVE-2025-64778","cvss":7.3,"epss":0.0012,"slug":"cve-2025-64778-nmis-biodose-software-v22-02-and-previous-versions-contain","title":"NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwo","severity":"high","exploited":false,"published_at":"2025-12-02T21:15:52.75+00:00","url":"https://junglewise.ai/threats/cve-2025-64778-nmis-biodose-software-v22-02-and-previous-versions-contain"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}