CVE-2016-6530
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of these passwords.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cret@cert.org — https://www.schickbysirona.com/items.php?itemid=19189
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| dentsply_sirona | cdr_dicom | {"endIncluding":"5.0"} | |
References
CWEs
CWE-798
Verify integrity in audit chain (admin only). AS-IS.