NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.
Advisories

No advisories yet.

Fixes

Solution

Mirion Medical recommends users update to V23.0 or later. Users with an active support contract should update to the latest version through the software or users can contact Mirion Medical support directly.


Workaround

No workaround given by the vendor.

History

Tue, 02 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.
Title Mirion Medical EC2 Software NMIS BioDose Use of Client-Side Authentication
Weaknesses CWE-603
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-12-02T21:39:30.055Z

Reserved: 2025-11-11T20:56:52.843Z

Link: CVE-2025-61940

cve-icon Vulnrichment

Updated: 2025-12-02T21:39:24.460Z

cve-icon NVD

Status : Received

Published: 2025-12-02T21:15:51.930

Modified: 2025-12-02T21:15:51.930

Link: CVE-2025-61940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.