CVE-2025-61940

8.3

Mirion Medical · EC2 Software NMIS BioDose

Mirion Medical NMIS/BioDose V22 and earlier versions use a common SQL Server account for database access, which can be bypassed by authenticated users to access unauthorized data.

Executive summary

A critical authentication and authorization flaw in Mirion Medical NMIS/BioDose allows authenticated users to bypass application restrictions and access the underlying database.

Vulnerability

The application relies on a shared database credential rather than individual user authentication, allowing any authenticated user to potentially perform unauthorized database operations. The vulnerability is triggered by a low-privileged authenticated user, as described by the CVSS vector PR:L.

Business impact

Successful exploitation allows an authenticated attacker to bypass intended application-level security controls and gain unauthorized access to sensitive medical data stored in the database. With a CVSS score of 8.3, this high-severity vulnerability poses a significant risk of data exfiltration and potential compromise of patient information, necessitating immediate attention to maintain regulatory compliance and data integrity.

Remediation

Immediate Action: Update the Mirion Medical EC2 Software NMIS BioDose installation to version 23.0 or later to enable the use of Windows user authentication for database connections.

Proactive Monitoring: Review database access logs for unusual queries or authentication patterns originating from the application service account.

Compensating Controls: Ensure that network access to the SQL Server hosting the NMIS BioDose database is strictly restricted to authorized application servers via firewall rules.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized data access, administrators must prioritize the upgrade to version 23.0. Implementing the transition to Windows-integrated authentication is the only effective way to remediate the underlying design flaw and ensure that database access is properly constrained by user identity.

Sources

Originally found and disclosed by Joe Dillon reported these vulnerabilities to Mirion Medical., per the CVE Program record.