← CVE Tracker
8.3HIGH

CVE-2025-62575 — NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database.

Mirion · Biodose/Nmis · Published 2 Dec 2025 · Modified 25 Sept 2026

Description

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.

References

What to do
  1. Check whether Biodose/Nmis is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-62575