PT-2018-1181 · Ge · Ge Infinia/Infinia With Hawkeye 4

Published

2018-02-06

·

Updated

2019-10-09

·

CVE-2017-14002

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions
Description The issue is related to the use of default or hard-coded credentials in the software. This could allow a remote attacker to bypass authentication and gain access to the affected devices.
Recommendations For all current versions, consider changing the default or hard-coded credentials to unique and strong passwords to prevent unauthorized access. As a temporary workaround, restrict access to the devices to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00639
CVE-2017-14002

Affected Products

Ge Infinia/Infinia With Hawkeye 4