PT-2018-1181 · Ge · Ge Infinia/Infinia With Hawkeye 4
Published
2018-02-06
·
Updated
2019-10-09
·
CVE-2017-14002
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions
Description
The issue is related to the use of default or hard-coded credentials in the software. This could allow a remote attacker to bypass authentication and gain access to the affected devices.
Recommendations
For all current versions, consider changing the default or hard-coded credentials to unique and strong passwords to prevent unauthorized access. As a temporary workaround, restrict access to the devices to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ge Infinia/Infinia With Hawkeye 4