MEDIUM · 5.0

CVE-2012-4952

Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customers' installations, which allows remote attackers to obtain sensitive information ...

Vulnerability Description

Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customers' installations, which allows remote attackers to obtain sensitive information about patients by leveraging knowledge of this password from another installation.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DentrixG5<= 15.1.293

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4952?

CVE-2012-4952 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customers' installations, which allows remote attackers to obtain sensitive information ...

How severe is CVE-2012-4952?

CVE-2012-4952 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4952?

Check the references section above for vendor advisories and patch information. Affected products include: Dentrix G5.