PT-2015-3516 · Ge Healthcare+2 · Ge Healthcare Centricity Analytics Server+2
Scott Erven
·
Published
2015-08-04
·
Updated
2018-03-28
·
CVE-2011-5322
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GE Healthcare Centricity Analytics Server version 1.1
Description
The issue concerns default passwords for various users in the GE Healthcare Centricity Analytics Server. Specifically, the default passwords are:
V0yag3r for the SQL Server sa user, G3car3s for the analyst user, G3car3s for the ccg user, V0yag3r for the viewer user, and geservice for the geservice user in the Webmin interface. The impact and attack vectors of this issue are not specified.Recommendations
For GE Healthcare Centricity Analytics Server version 1.1, change the default passwords for all users, including the SQL Server
sa user, analyst user, ccg user, viewer user, and geservice user in the Webmin interface, to strong, unique passwords to prevent unauthorized access.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Healthcare Centricity Analytics Server
Sql Server
Webmin