---
id: CVE-2025-62575
title: >-
  NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server
  database
summary: >-
  NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server
  database. The SQL user account 'nmdbuser' and other created accounts by
  default have the sysadmin role. This can lead to remote code execution through
  the use of ce…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-732
vendor: mirion
product: biodose/nmis
affected:
  - biodose/nmis < 23.0
patched:
  - biodose/nmis 23.0
published: '2025-12-02'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62575'
references:
  - url: 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.0042
epssPercentile: 0.33667
ingestedAt: '2026-09-25T23:21:16.867Z'
---

## Overview

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.

## Affected

- `biodose/nmis < 23.0`

## Remediation

Upgrade past the affected range:

- `biodose/nmis 23.0`
