Vulnerability Description
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mirion | Biodose\/Nmis | < 23.0 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01Third Party Advisory
FAQ
What is CVE-2025-62575?
CVE-2025-62575 is a vulnerability with a CVSS score of 8.3 (HIGH). NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote...
How severe is CVE-2025-62575?
CVE-2025-62575 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62575?
Check the references section above for vendor advisories and patch information. Affected products include: Mirion Biodose\/Nmis.