CVE
- Id
- 93351
- CVE No.
- CVE-2016-6531
- Status
- Candidate
- Description
- ** DISPUTED ** Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulnerability note ... is factually false ... there is indeed a default blank password, but it can be changed ... We recommend that users change it, each customer receives direction."
- Phase
- Assigned (20160803)
- Votes
- None (candidate not yet proposed)
- Comments