Lucene search

K
cveIcscertCVE-2020-36548
HistoryJun 17, 2022 - 1:15 p.m.

CVE-2020-36548

2022-06-1713:15:11
CWE-287
icscert
web.nvd.nist.gov
33
2
cve-2020-36548
ge voluson s8
vulnerability
improper authentication
elevated access
uscgi-bin
local host
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

12.6%

A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibilities. It is possible to launch the attack on the local host.

Affected configurations

Nvd
Node
gevoluson_s8_firmwareMatch-
AND
gevoluson_s8Match-
VendorProductVersionCPE
gevoluson_s8_firmware-cpe:2.3:o:ge:voluson_s8_firmware:-:*:*:*:*:*:*:*
gevoluson_s8-cpe:2.3:h:ge:voluson_s8:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Voluson S8",
    "vendor": "GE",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2020-36548