MPDV Mikrolab MIP 2
cpe:2.3:h:mirion:drm-1/2:*:*:*:*:*:*:*, +7 more
- >= 8, <= 36/2025
A local file disclosure vulnerability has been identified in MPDV Mikrolab's HYDRA X, MIP 2, and FEDRA 2 products, all versions prior to Maintenance Pack 36 with Service Pack 8 (week 36/2025). This vulnerability allows an unauthenticated attacker to read arbitrary files from the Windows operating system where the software is installed. The issue arises in the 'Filename' parameter of the public '$SCHEMAS$' resource, and can be easily exploited.
Exploitation of this vulnerability allows for unauthorized access to local files on the Windows operating system, potentially leading to the disclosure of sensitive information.
The vulnerability can be reproduced by sending an HTTP GET request to the '$SCHEMAS$' resource with the 'Filename' parameter set to the path of a file on the Windows operating system, such as 'c:\windows\win.ini'.
Users are advised to upgrade to Maintenance Pack 36 for MIP 2, FEDRA 2, or HYDRA X with Service Pack 8, week 36/2025. The patch is available through the vendor's support portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.