Mirion Medical NMIS BioDose Incorrect Permission Assignment Vulnerability Leading to Remote Code Execution
Vulnerability
A vulnerability exists in Mirion Medical's NMIS/BioDose software versions through 22.02, due to incorrect permission assignments that grant the SQL user 'nmdbuser' and other default accounts sysadmin roles. This misconfiguration allows for remote code execution by exploiting certain built-in stored procedures. Additionally, the application's installation directory may have insecure file permissions, potentially enabling users on client workstations to modify program executables and libraries.
Impact
Exploitation of this vulnerability could lead to unauthorized access to the SQL Server database, allowing attackers to execute arbitrary code on the server.
Remediation
Users are advised to update to version 23.0 or later. Those with an active support contract can contact Mirion Medical support for assistance.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
