CVE-2025-61940
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
02/12/2025
Last modified:
04/12/2025
Description
NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.30
Severity 3.x
HIGH



