CVE-2017-2853: Natus Xltek Neuroworks

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

Affected products

  • Natus Xltek Neuroworks: version 8 only

Published 2018-04-05. Last modified 2026-06-17.