Opendental

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    2
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2018-15718

    Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt. This allows the attacker to gain access to usernames, password hashes, privilege levels, and more.

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2018

    CVE-2018-15719

    Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2018

    CVE-2018-15717

    Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2018

    CVE-2016-6531

    Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulnerability note ... is factually false ... there is indeed a default blank password, but it can be changed ... We recommend that users change it, each customer receives direction.

    Last Modified: Apr 12, 2025
    Published: Sep 24, 2016
    Items Per Page
    Opendental Vulnerabilities & Security CVEs | CVE-DB