CVE-2023-47800
10.11.2023, 07:15
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.Enginsight
Vendor | Product | Version |
---|---|---|
natus | neuroworks_eeg | 𝑥 < 8.4 |
natus | neuroworks_eeg | 8.4 |
natus | sleepworks | 𝑥 < 8.4 |
natus | sleepworks | 8.4 |
𝑥
= Vulnerable software versions
References