Vulnerability Description
Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customers' installations, which allows remote attackers to obtain sensitive information about patients by leveraging knowledge of this password from another installation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dentrix | G5 | <= 15.1.293 |
Related Weaknesses (CWE)
References
- http://www.dentrix.com/support/software-updates/g5.aspxVendor Advisory
- http://www.kb.cert.org/vuls/id/948155US Government Resource
- http://www.kb.cert.org/vuls/id/JALR-8ZRHUKUS Government Resource
- http://www.dentrix.com/support/software-updates/g5.aspxVendor Advisory
- http://www.kb.cert.org/vuls/id/948155US Government Resource
- http://www.kb.cert.org/vuls/id/JALR-8ZRHUKUS Government Resource
FAQ
What is CVE-2012-4952?
CVE-2012-4952 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customers' installations, which allows remote attackers to obtain sensitive information ...
How severe is CVE-2012-4952?
CVE-2012-4952 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4952?
Check the references section above for vendor advisories and patch information. Affected products include: Dentrix G5.