Critical severity9.8NVD Advisory· Published Nov 10, 2023· Updated Jun 17, 2026
CVE-2023-47800
CVE-2023-47800
Description
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:natus:neuroworks_eeg:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:natus:neuroworks_eeg:*:*:*:*:*:*:*:*range: <8.4
- cpe:2.3:a:natus:neuroworks_eeg:8.4:-:*:*:*:*:*:*
cpe:2.3:a:natus:sleepworks:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:natus:sleepworks:*:*:*:*:*:*:*:*range: <8.4
- cpe:2.3:a:natus:sleepworks:8.4:-:*:*:*:*:*:*
- (no CPE)range: <8.4 GMA3
- Natus/NeuroWorks and SleepWorksdescription
- Range: <8.4 GMA3
Patches
Vulnerability mechanics
References
2- www.trustwave.com/hubfs/Web/Library/Advisories_txt/TWSL2023-006.txtnvdExploitThird Party Advisory
- partner.natus.com/m/7cd3bcca88e446d4/original/NeuroWorks-SleepWorks-Product-Security-Bulletin.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.