{ "id": "CVE-2021-35193", "sourceIdentifier": "cve@mitre.org", "published": "2021-07-30T19:15:09.370", "lastModified": "2021-08-11T15:25:11.357", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installations (that have the same software version). This provides remote access to SQL database credentials. (In the normal use of the product, retrieving those credentials only occurs after a username/password authentication step; however, this authentication step is on the client side, and an attacker can develop their own client that skips this step.)" }, { "lang": "es", "value": "El Servicio de Aplicaciones de Patterson en Patterson Eaglesoft versiones 18 hasta 21, acepta la misma autenticaci\u00f3n de certificado a trav\u00e9s de las instalaciones de diferentes clientes (que presentan la misma versi\u00f3n de software). Esto proporciona acceso remoto a las credenciales de la base de datos SQL. (En el uso normal del producto, recuperando esas credenciales s\u00f3lo se produce despu\u00e9s de un paso de autenticaci\u00f3n de nombre de usuario y contrase\u00f1a; sin embargo, este paso de autenticaci\u00f3n est\u00e1 en el lado del cliente, y un atacante puede desarrollar su propio cliente que salte este paso)" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-295" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:pattersondental:eaglesoft:*:*:*:*:*:*:*:*", "versionStartIncluding": "18.0", "versionEndIncluding": "21.0", "matchCriteriaId": "76418DF5-4706-464C-AC67-F6F9435EE544" } ] } ] } ], "references": [ { "url": "http://patterson.eaglesoft.net/Home/Contact-Us", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "https://github.com/jshafer817/Eaglesoft", "source": "cve@mitre.org", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "https://justinshafer.blogspot.com/2021/07/eaglesoft-18-through-21-vulnerability.html", "source": "cve@mitre.org", "tags": [ "Exploit", "Third Party Advisory" ] } ] }