CVE-2016-6531
Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulnerability note ... is factually false ... there is indeed a default blank password, but it can be changed ... We recommend that users change it, each customer receives direction.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.49% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- opendental/opendental
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/619767Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/GWAN-ACVSBMThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/92780
- http://www.kb.cert.org/vuls/id/619767Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/GWAN-ACVSBMThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/92780
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.