CVE-2025-62575HIGH 8.3EPSS p34.2%
CVE-2025-62575CVE-2025-62575
mirion / biodose\/nmis
Description
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.
Scoring
| CVSS 3.1 | 8.3 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| EPSS | 0.42% probability of exploitation · percentile 34.2% · 2026-10-06T12:00:23Z |
| Published | 2025-12-02 |
| Last modified | 2026-09-25 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Permission Assignment for Critical Resourcecwe-732 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.