Mirion develops radiation detection and measurement instruments and associated software platforms, with a focused product portfolio centered on dosimetry monitoring systems such as BioDose/NMIS and its DRM dosimeter-reader product line. The recurring vulnerability pattern across these products reflects the combination of legacy embedded firmware, field-deployed hardware, and direct access-control demands: permission assignment errors, weak encryption implementations, client-side authentication logic, and hard-coded credentials recur as characteristic exposures in this class of specialized instrumentation. Defenders should prioritize inventory and network segmentation for affected dosimeters and associated software, particularly where these systems connect to broader monitoring networks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mirion over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62575HIGH NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. Thi | Dec 2, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-61940HIGH NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password | Dec 2, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-64642HIGH NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client | Dec 2, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-64298HIGH NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked inst | Dec 2, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-64778HIGH NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to b | Dec 2, 2025 | 7.8 | 23 | NO | NO |
CVE-2017-9645MEDIUM An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM | Sep 20, 2017 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mirion.
Media articles that mention a CVE ID that affects a product developed by Mirion — matched by CVE ID, not by vendor name.