PT-2024-3918 · Ge Healthcare · Common Service Desktop

Published

2024-02-19

·

Updated

2024-05-17

·

CVE-2024-1629

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Common Service Desktop (affected versions not specified)
Description: The issue concerns a path traversal vulnerability in the deleteFiles() function of Common Service Desktop, a component of GE HealthCare ultrasound devices. This vulnerability is related to incorrect restriction of directory path names with limited access. Exploitation of this issue may allow an attacker to gain unauthorized access to protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-04328
CVE-2024-1629

Affected Products

Common Service Desktop