VYPR
Critical severity9.8NVD Advisory· Published Apr 1, 2016· Updated May 6, 2026

CVE-2016-2343

CVE-2016-2343

Description

Patterson Dental Eaglesoft 17 uses a hardcoded database password (sql) for the dba account, enabling remote attackers to access sensitive patient data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Patterson Dental Eaglesoft 17 uses a hardcoded database password (sql) for the dba account, enabling remote attackers to access sensitive patient data.

Vulnerability

Patterson Dental Eaglesoft version 17 (and possibly other versions) contains a hardcoded database password of sql for the dba account [1]. This credential is shared across all installations and cannot be changed by administrators without breaking database access [1]. The vulnerability is classified as CWE-798: Use of Hard-coded Credentials [1].

Exploitation

An attacker with network access to the Eaglesoft database can use the known hardcoded credentials (dba / sql) to authenticate and execute arbitrary SQL statements [1]. No authentication or user interaction is required beyond network connectivity to the database service [1]. The attacker does not need prior access to the Eaglesoft application itself.

Impact

Successful exploitation allows the attacker to retrieve sensitive patient information stored in the Dental.DB database, including personal health records [1]. The impact is a breach of confidentiality; the attacker gains read access to the entire database contents without any privilege escalation [1].

Mitigation

As of the CERT/CC publication date (2016-03-30), no vendor-supplied fix was available [1]. The recommended workarounds include restricting network access to the database to trusted hosts and networks, and ensuring the database is not accessible over insecure wireless networks (use WPA2 encryption, disable WPS) [1]. Administrators cannot change the hardcoded password without breaking database functionality [1]. The product may be considered end-of-life; users should consult the vendor for current support status.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:patterson_dental:eaglesoft:17.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:patterson_dental:eaglesoft:17.0:*:*:*:*:*:*:*
    • (no CPE)range: = 17

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.