The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding multiple high-severity vulnerabilities in the BioDose/NMIS software, a nuclear medicine inventory tracking solution developed by EC2 Software and owned by Mirion Medical. These vulnerabilities, present in versions prior to 23.0, could allow attackers to modify program executables, execute code remotely, and access sensitive information if exploited. The software is widely used in nuclear medicine and radiology departments, raising concerns about the potential impact on healthcare operations and data security.
Mirion Medical has confirmed that the identified flaws have been addressed in the latest release of the software. The company stated that it acted promptly upon learning of the vulnerabilities, working in coordination with CISA and its customers to deliver fixes and mitigate risk. Organizations using affected versions are strongly advised to update to the latest release to ensure protection against these critical security issues.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
CISA issued an advisory warning that multiple high-severity vulnerabilities in BioDose/NMIS could allow attackers to modify executables, access sensitive information, and in some cases achieve remote code execution. The agency said the affected product is used worldwide.
Mirion Medical said it coordinated disclosure with CISA and others and remediated the reported vulnerabilities in BioDose/NMIS Version 23. The flaws affected versions prior to 23.0.
An independent researcher identified and reported five high-severity vulnerabilities in EC2 Software's BioDose/NMIS nuclear medicine inventory tracking software. The issues included incorrect permission assignments, a client-side authentication weakness, and hard-coded credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.