Security Advisory

CVE-2025-64298

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-02 21:05:38
Last updated 2025-12-09 17:03:09
Assigner icscert
State PUBLISHED

Description

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.