NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.
Advisories

No advisories yet.

Fixes

Solution

Mirion Medical recommends users update to V23.0 or later. Users with an active support contract should update to the latest version through the software or users can contact Mirion Medical support directly.


Workaround

No workaround given by the vendor.

History

Tue, 09 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Mirion Medical
Mirion Medical nmis Biodose
Vendors & Products Microsoft
Microsoft windows
Mirion Medical
Mirion Medical nmis Biodose

Tue, 02 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.
Title Mirion Medical EC2 Software NMIS BioDose Use of Client-Side Authentication
Weaknesses CWE-603
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-12-09T17:03:27.576Z

Reserved: 2025-11-11T20:56:52.843Z

Link: CVE-2025-61940

cve-icon Vulnrichment

Updated: 2025-12-02T21:39:24.460Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-02T21:15:51.930

Modified: 2025-12-04T17:15:08.283

Link: CVE-2025-61940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-04T16:44:41Z

Weaknesses