CVE-2025-61940: Mirion Biodose/nmis
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.
Affected products
- Mirion Biodose/nmis: before 23.0 (fixed in 23.0)
Published 2025-12-02. Last modified 2026-09-25.