CVE-2025-64778: Hardcoded Credentials Vulnerability in NMIS/BioDose

ISGroup Cybersecurity

NMIS/BioDose is a specialized software platform used in medical and clinical environments for nuclear medicine tracking and biodosimetry. Given its application in the healthcare sector, the system likely processes and stores highly sensitive Protected Health Information (PHI), making it a critical component of clinical operations and a high-value target for attackers.

Compromising this system represents a significant business risk. The vulnerability allows an attacker with access to the application binaries to extract hard-coded credentials, potentially gaining administrative-level access to the application and its backend database. This could lead to a major data breach, violating regulatory requirements such as HIPAA and resulting in significant financial penalties and reputational damage.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding this vulnerability, highlighting its risk to critical infrastructure. While there are no public reports of active exploitation, a public exploit is available, which increases the likelihood of opportunistic or targeted attacks. The primary risk concerns environments where unauthorized individuals can access the application installation files on the server file system.

ProductNMIS/BioDose
Date2025-12-05 00:30:55

Technical Summary

The root cause of this vulnerability is the practice of storing static credentials directly in the compiled application binaries, classified as CWE-798: Use of Hard-coded Credentials. These credentials, such as database connection strings or administrative passwords, are stored in plain text or in an easily reversible format, allowing for easy extraction by an attacker with access to the executable files.

An attacker can exploit this vulnerability by following these steps:

  1. An attacker first gains access to the NMIS/BioDose application binaries, either by compromising a separate system or by obtaining the software installer.
  2. Using standard binary analysis tools (e.g., strings, Ghidra, IDA Pro), the attacker inspects the executable files for static character sequences that appear to be credentials.
  3. Once the credentials are extracted, the attacker can use them to authenticate directly to the application database or administrative interfaces.
  4. This grants the attacker the same privileges as the hard-coded account, which may include full read, write, and delete access to sensitive patient data and system configurations.
// Conceptual example of a hard-coded credential anti-pattern
// DO NOT USE THIS CODE
public class DatabaseManager
{
    public IDbConnection CreateConnection()
    {
        // VULNERABILITY: Credentials are hard-coded in the source code.
        // An attacker can discover this string by analyzing the compiled binary.
        string dbConnectionString = "Server=prod_db;Database=BioDose;User Id=biodose_admin;Password=HardCodedP@ssw0rd!;";
        var connection = new SqlConnection(dbConnectionString);
        connection.Open();
        return connection;
    }
}

Affected versions: NMIS/BioDose V22.02 and all previous versions are vulnerable.
Fix availability: A fix is available. Users should consult the vendor documentation for the specific patched version.

Recommendations

  • Apply the patch immediately: Update NMIS/BioDose to a version later than V22.02. Consult vendor (Mirion Medical) advisories for details on the patched version and installation instructions.
  • Mitigations and Hardening:
    • Implement strict file system permissions (ACLs) on the application installation directory to ensure that only authorized administrative accounts have read access to the binaries.
    • If allowed by the application configuration, immediately change any default or hard-coded passwords. If this is not possible, treat the credentials as compromised and implement enhanced monitoring.

  • Investigation and Monitoring:

    • Verify all authentication logs for the NMIS/BioDose application and its backend database. Investigate any successful logins from unusual IP addresses, anomalous geographic locations, or activity at unusual hours.
    • Monitor for any signs of mass data exfiltration from the application database, including anomalous network traffic patterns.
    • Search for unauthorized copies of the application binaries on other systems within the environment.

  • Incident Response:

    • If a compromise is suspected, immediately isolate the host running the software and the related database from the network to prevent lateral movement.
    • If credentials have been compromised, rotate them immediately if possible.
    • Initiate a forensic investigation to determine the extent of the data breach, with particular attention to the potential exposure of Protected Health Information (PHI) in order to establish any regulatory reporting obligations.

  • Defense in Depth:

    • Apply network segmentation to restrict access to the database server exclusively to the application server.
    • Apply the principle of least privilege to all accounts and services associated with the NMIS/BioDose application.
    • Ensure that comprehensive and tested data backup and recovery procedures are in place.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert