Lucene search

K
cvelistIcscertCVELIST:CVE-2020-36548
HistoryJun 17, 2022 - 1:10 p.m.

CVE-2020-36548 GE Voluson S8 Service Browser users.cgi improper authentication

2022-06-1713:10:18
CWE-287
icscert
www.cve.org
4
ge voluson s8
service browser
users.cgi vulnerability
improper authentication
elevated access

CVSS3

5.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0

Percentile

12.6%

A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibilities. It is possible to launch the attack on the local host.

CNA Affected

[
  {
    "product": "Voluson S8",
    "vendor": "GE",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2020-36548