CVE-2025-64778: Hardcoded Password Vulnerability in NMIS/BioDose Allows Unauthorized Access

ISGroup Cybersecurity

NMIS/BioDose is a specialized software suite used in sensitive environments for network management and, in particular, for monitoring radiation exposure in nuclear medicine. As it is deployed in healthcare and research facilities, it often processes and stores highly sensitive data related to patients and operations, making it a high-value target for attackers.

The primary risk stems from the use of hardcoded credentials directly within the software, which provide a direct path for privilege escalation. An attacker with even minimal read access to the filesystem can easily extract these credentials and gain administrative control of the application and its database. Although no confirmed attacks exploiting this vulnerability in an active manner have been recorded yet, its inclusion in a CISA advisory for Industrial Control Systems (ICS) highlights its criticality. All instances, both internal and internet-facing, of the vulnerable versions must be considered high-risk due to the simplicity of exploitation once initial access is obtained.

ProductNMIS/BioDose
Date2025-12-04 12:31:29

Technical Summary

The root cause of this vulnerability is classified as CWE-798: Use of Hard-coded Credentials. Passwords for the application and the associated database are stored in plaintext directly within the application’s executable binary files. This insecure practice eliminates the need for advanced reverse engineering techniques, as the credentials can be retrieved using simple file inspection tools.

The attack chain is straightforward:

  1. An attacker gains initial access to the filesystem of the server where the NMIS/BioDose software is installed.
  2. The attacker uses a standard utility, such as strings, to read the content of the application’s binary files.
  3. The hardcoded passwords are found in plaintext within the data segments of the binary.
  4. The attacker uses these credentials to access the application or its database with administrative privileges.

A conceptual representation of the vulnerable code logic is as follows:

// -- VULNERABLE CODE (CONCEPTUAL) --
// Database credentials are compiled directly into the application,
// making them readable by anyone with access to the binary.

void connectToDatabase() {
    const char* user = "biodose_admin";
    const char* pass = "h@rdc0d3d_p@ssw0rd_Examp1e!"; // Plaintext password in binary
    db_connect("127.0.0.1", user, pass);
}

Affected versions: NMIS/BioDose V22.02 and earlier are vulnerable.
Patch availability: A corrected version has been released, and users must update to the latest version available from the vendor.

Successful exploitation allows an attacker to gain full administrative access, enabling the reading, modification, or exfiltration of sensitive data related to network management and patient radiation exposure records.

Recommendations

  • Apply the patch immediately: Update all instances of NMIS/BioDose to a version later than V22.02. Contact the vendor to obtain the latest corrected version of the software and deployment instructions.

  • Mitigations:

  • Implement strict access controls on the filesystem. Ensure that only trusted administrative accounts can read or execute files in the application’s binary directory.

  • If updating is not immediately possible, use application control or whitelisting solutions to prevent unauthorized processes from accessing NMIS/BioDose binary files.

  • Detection and Monitoring:

  • Check application and database logs for unauthorized or anomalous login activity. Correlate access times with activity on the host system.

  • Monitor command-line activity related to the use of tools such as strings, grep, or cat on the application’s executable files.

  • Establish a baseline of normal network connections to the database and generate alerts for connections from unexpected sources.

  • Incident Response:

  • In case of suspected compromise, immediately rotate all credentials associated with the NMIS/BioDose application and its database after applying the patch.

  • Isolate the compromised host from the network to prevent potential lateral movement.

  • Assume that all data handled by the application has been compromised and initiate a forensic investigation to determine the extent of the breach.

  • Defense in Depth:

  • Employ network segmentation to ensure that the database server only accepts connections from the application server.

  • Regularly review user and service account privileges, applying the principle of least privilege.

  • Ensure you have robust backup and recovery procedures for all critical application data.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert