← Back to browse · API

CVE-2017-2853

Severity
CRITICAL
CVSS
10.0
EPSS
0.03383
Risk score
41.18
CISA KEV
No
PoC
No
Published
2018-04-05
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2017-11994, GHSA-MQCQ-679Q-9MCM
Products
Natus Medical Incorporated:Natus Natus Xltek NeuroWorks 8
Sources
euvd EUVD-2017-11994

Description

An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

References