Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85qp-mxrm-pxg7

Опубликовано: 10 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.

EPSS

Процентиль: 88%
0.03682
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.

EPSS

Процентиль: 88%
0.03682
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798