Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a...
Critical severity
Unreviewed
Published
Nov 10, 2023
to the GitHub Advisory Database
•
Updated Dec 1, 2023
Description
Published by the National Vulnerability Database
Nov 10, 2023
Published to the GitHub Advisory Database
Nov 10, 2023
Last updated
Dec 1, 2023
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.
References