Overview
Patterson Dental Eaglesoft is a dental records software. Eaglesoft uses a hard-coded database password that is shared across all installations.
Description
CWE-798: Use of Hard-coded Credentials - CVE-2016-2343 According to the researcher, Eaglesoft uses hard-coded credentials to access a database back-end. The credentials are the same across installations of Eaglesoft. Sensitive patient information is contained in Eaglesoft databases. An administrator is unable to change these credentials without breaking access to the back-end database. |
Impact
An attacker with knowledge of the hard-coded credentials and with network access to the database may be able to obtain sensitive patient information. |
Solution
The CERT/CC is currently unaware of a full solution to this problem. |
Restrict Network Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 9.5 | E:F/RL:U/RC:C |
Environmental | 2.4 | CDP:ND/TD:L/CR:H/IR:H/AR:ND |
References
Acknowledgements
Thanks to Justin Shafer for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2016-2343 |
Date Public: | 2016-02-15 |
Date First Published: | 2016-03-30 |
Date Last Updated: | 2016-03-30 15:00 UTC |
Document Revision: | 43 |