CVE-2023-47800

CRITICAL

Natus NeuroWorks and SleepWorks < 8.4 GMA3 - Use of Hard-coded Credentials in MSSQL sa Account

Title source: llm
STIX 2.1

Description

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.

Scores

CVSS v3 9.8
EPSS 0.0141
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (4)
natus/neuroworks_eeg 8.4
natus/neuroworks_eeg < 8.4
natus/sleepworks 8.4
natus/sleepworks < 8.4
Published Nov 10, 2023
Tracked Since Feb 18, 2026