Unprotected Exposed Firebird Database with default credentials
No sign of exploitation. No public exploitation artifact known so far.
A medical office database (Firebird) uses default passwords that anyone on the local network can guess, allowing attackers to access patient records and login credentials. The attacker can also create or modify files on the server with system-level privileges.
Firebird database exposed on the network with unchanged default credentials (CWE-1393), permitting unauthenticated remote DBA access from local network attackers. The vulnerability enables unauthorized data exfiltration of patient information and credentials, and arbitrary file write/modification on the server filesystem with NT AUTHORITY\SYSTEM privileges (CWE-419), facilitating privilege escalation and lateral movement.