Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
GE HealthCare · Invenia ABUSGE HealthCare · Invenia ABUS 2.0GE HealthCare · LOGIQ eGE HealthCare · LOGIQ HeGE HealthCare · VenueGE HealthCare · Venue FitGE HealthCare · Venue GoGE HealthCare · Vivid EGE HealthCare · Vivid iqGE HealthCare · Vivid SGE HealthCare · Vivid TReferences
https://securityupdate.gehealthcare.com/