CERT-In Vulnerability Note
CIVN-2020-0446
Information Disclosure Vulnerabilities in GE Healthcare Products
Original Issue Date:December 24, 2020
Severity Rating: HIGH
Systems Affected
- GE Imaging and Ultrasound Products
Overview
A vulnerability has been reported in GE Imaging and Ultrasound Products which could allow a remote attacker to gain access or modify the sensitive information on the targeted system.
Description
1. Information Disclosure Vulnerability
(
CVE-2020-25175
)
This vulnerability exists in GE Healthcare Imaging and Ultrasound Products due to unprotected transport of credentials. A remote attacker could exploit this vulnerability by gaining access to the network. Successful exploitation of this vulnerability could allow attacker to gain access to sensitive information on the targeted system.
2. Information Disclosure Vulnerability
(
CVE-2020-25179
)
This vulnerability exists in GE Healthcare Imaging and Ultrasound Products because they allow exposed/default credentials to be utilized to access the system. An attacker could exploit this vulnerability by gaining access to the network. Successful exploitation of this vulnerability could allow attacker to gain access or modify the sensitive information on the targeted system.
Solution
GE recommends users refer to the GE Healthcare Product Security Portal.
https://www.gehealthcare.com/en-US/security
Vendor Information
GE Healthcare
https://www.gehealthcare.com/
References
GE Healthcare
https://us-cert.cisa.gov/ics/advisories/icsma-20-343-01
CVE Name
CVE-2020-25175
CVE-2020-25179
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|