VDB
CVE-2016-6531
CVE-2016-6531
PUBLISHED
CVSS 7.5 HIGH
Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulnerability note ... is factually false ... there is indeed a default blank password, but it can be changed ... We recommend that users change it, each customer receives direction.
EPSS 3.27% · 87.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
3.27%
87.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| opendental | opendental | 0 |
| n/a | n/a | n/a |
Timeline
- Sep 24, 2016 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 24, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- VU#619767 third-party-advisory
- 92780 vdb
- http://www.kb.cert.org/vuls/id/GWAN-ACVSBM url
- https://nvd.nist.gov/vuln/detail/CVE-2016-6531 advisory