Mirion Medical NMIS BioDose Incorrect Permission Assignment Vulnerability Leading to Remote Code Execution

Vulnerability

A vulnerability exists in Mirion Medical's NMIS/BioDose software versions through 22.02, due to incorrect permission assignments that grant the SQL user 'nmdbuser' and other default accounts sysadmin roles. This misconfiguration allows for remote code execution by exploiting certain built-in stored procedures. Additionally, the application's installation directory may have insecure file permissions, potentially enabling users on client workstations to modify program executables and libraries.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the SQL Server database, allowing attackers to execute arbitrary code on the server.

Remediation

Users are advised to update to version 23.0 or later. Those with an active support contract can contact Mirion Medical support for assistance.

Added: Dec 2, 2025, 9:20 PM
Updated: Dec 2, 2025, 9:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.8
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.