CVE-2023-47800

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
10/11/2023
Last modified:
23/11/2023

Description

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:natus:neuroworks_eeg:*:*:*:*:*:*:*:* 8.4 (excluding)
cpe:2.3:a:natus:neuroworks_eeg:8.4:-:*:*:*:*:*:*
cpe:2.3:a:natus:sleepworks:*:*:*:*:*:*:*:* 8.4 (excluding)
cpe:2.3:a:natus:sleepworks:8.4:-:*:*:*:*:*:*