PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-62575 Mirion Medical CVE debrief

CVE-2025-62575 affects Mirion Medical EC2 Software NMIS/BioDose V22.02 and earlier. According to CISA, the default SQL user account 'nmdbuser' and other created accounts have the sysadmin role, which can enable remote code execution through built-in Microsoft SQL Server stored procedures. Mirion Medical advises updating to V23.0 or later.

Vendor
Mirion Medical
Product
EC2 Software NMIS BioDose
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-02
Original CVE updated
2026-09-25
Advisory published
2025-12-02
Advisory updated
2026-09-25

Who should care

Organizations running Mirion Medical EC2 Software NMIS/BioDose, especially database administrators, OT/ICS operators, system administrators, and security teams responsible for SQL Server hardening and patching.

Technical summary

The advisory states that NMIS/BioDose V22.02 and previous versions rely on Microsoft SQL Server and that the 'nmdbuser' account, along with other created accounts, is granted sysadmin by default. The supplied CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) indicates a network-exploitable issue requiring low privileges. With sysadmin-level SQL access, built-in stored procedures can be abused to reach remote code execution.

Defensive priority

High. The issue is rated CVSS 8.3 (HIGH) and impacts default database privileges in a product line used in medical/industrial contexts. Prioritize upgrading exposed or actively used installations, then verify SQL account privilege assignments.

Recommended defensive actions

  • Update Mirion Medical EC2 Software NMIS/BioDose to V23.0 or later.
  • If you have an active support contract, apply the latest vendor-provided update through the software or contact Mirion Medical support.
  • Review SQL Server accounts used by the application and remove unnecessary sysadmin privileges.
  • Audit for other default or created database accounts with elevated roles and restrict them to least privilege.
  • Validate that only required administrative access is allowed to the SQL Server hosting the application.
  • Use CISA ICS recommended practices and defense-in-depth guidance to harden and monitor the environment.

Evidence notes

This debrief uses only the supplied CISA CSAF advisory content, the embedded CVSS vector, the CVE record reference, and the vendor remediation statement. No exploit steps, reproduction details, or unsupported environmental assumptions are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-62575 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-62575

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-62575 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62575

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-336-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-336-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.