NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mirion Medical
Mirion Medical nmis Biodose |
|
| Vendors & Products |
Mirion Medical
Mirion Medical nmis Biodose |
Tue, 02 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures. | |
| Title | Mirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical Resource | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-12-02T21:37:46.825Z
Reserved: 2025-11-11T20:56:52.854Z
Link: CVE-2025-62575
Updated: 2025-12-02T21:37:36.594Z
Status : Awaiting Analysis
Published: 2025-12-02T21:15:52.133
Modified: 2025-12-04T17:15:08.283
Link: CVE-2025-62575
No data.