Natus operates a focused line of neurophysiology and sleep-monitoring software products, including NeuroWorks EEG and SleepWorks systems, that serve clinical and diagnostic environments where data integrity and system availability are critical. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety weaknesses including out-of-bounds reads and writes, as well as hard-coded credentials that compromise access control in medical-grade applications. Defenders should prioritize patching and network segmentation for these products given their deployment in healthcare settings; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Natus over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2853CRITICAL An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a sta | Apr 5, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-2867CRITICAL An exploitable code execution vulnerability exists in the SavePatientMontage functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer | Apr 5, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-2869CRITICAL An exploitable code execution vulnerability exists in the OpenProducer functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overfl | Apr 5, 2018 | 9.8 | 29 | NO | NO |
CVE-2023-47800CRITICAL Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code | Nov 10, 2023 | 9.8 | 27 | NO | NO |
CVE-2017-2868CRITICAL An exploitable code execution vulnerability exists in the NewProducerStream functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer o | Apr 5, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-2861HIGH An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream command in Natus Xltek NeuroWorks 8. A specially crafted network packet | Apr 5, 2018 | 7.5 | 25 | NO | NO |
CVE-2017-2858HIGH An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bo | Jun 1, 2018 | 7.5 | 23 | NO | NO |
CVE-2017-2860HIGH An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out | Jun 1, 2018 | 7.5 | 21 | NO | NO |
CVE-2017-2852HIGH An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out | Jun 1, 2018 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Natus.
Media articles that mention a CVE ID that affects a product developed by Natus — matched by CVE ID, not by vendor name.