Vulnerability Description
Patterson Dental Eaglesoft 17 has a hardcoded password of sql for the dba account, which allows remote attackers to obtain sensitive Dental.DB patient information via SQL statements.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Patterson Dental | Eaglesoft | 17.0 |
References
- http://justinshafer.blogspot.com/2016/02/moving-onto-eaglesoft-aka-patterson.htm
- http://www.kb.cert.org/vuls/id/344432Third Party AdvisoryUS Government Resource
- http://justinshafer.blogspot.com/2016/02/moving-onto-eaglesoft-aka-patterson.htm
- http://www.kb.cert.org/vuls/id/344432Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2016-2343?
CVE-2016-2343 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Patterson Dental Eaglesoft 17 has a hardcoded password of sql for the dba account, which allows remote attackers to obtain sensitive Dental.DB patient information via SQL statements.
How severe is CVE-2016-2343?
CVE-2016-2343 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-2343?
Check the references section above for vendor advisories and patch information. Affected products include: Patterson Dental Eaglesoft.