CVE-2023-47800: Natus Neuroworks Eeg
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.
Affected products
- Natus Neuroworks Eeg: before 8.4 (fixed in 8.4); version 8.4 only
- Natus Sleepworks: before 8.4 (fixed in 8.4); version 8.4 only
Published 2023-11-10. Last modified 2026-06-17.