Lucene search

K
cvelistIcscertCVELIST:CVE-2020-36547
HistoryJun 17, 2022 - 1:10 p.m.

CVE-2020-36547 GE Voluson S8 Service Browser hard-coded credentials

2022-06-1713:10:17
CWE-798
icscert
www.cve.org
4
ge voluson s8 service browser hard-coded credentials
critical vulnerability
local attack
configuration settings

CVSS3

5.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0

Percentile

12.6%

A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change the configuration settings.

CNA Affected

[
  {
    "product": "Voluson S8",
    "vendor": "GE",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2020-36547