PT-2022-8996 · Ge · Ge Voluson S8
Marc Ruef
+1
·
Published
2022-06-17
·
Updated
2022-06-30
·
CVE-2020-36547
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GE Voluson S8 (affected versions not specified)
Description
A critical issue affects the Service Browser, which introduces hard-coded credentials. Local attack is required to exploit this issue. It is recommended to change the configuration settings to mitigate the risk.
Recommendations
Change the configuration settings to remove or alter the hard-coded credentials in the Service Browser.
As a temporary workaround, consider restricting local access to the Service Browser until the configuration settings are updated.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Voluson S8