PT-2022-8997 · Ge · Ge Voluson S8

Marc Ruef

+1

·

Published

2022-06-17

·

Updated

2022-06-30

·

CVE-2020-36548

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GE Voluson S8 (affected versions not specified)
Description A vulnerability has been found in the file /uscgi-bin/users.cgi of the Service Browser, leading to improper authentication and elevated access possibilities. The attack can be launched on the local host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36548

Affected Products

Ge Voluson S8