Vulnerability CVE-2002-2445


Published: 2015-08-04

Description:
GE Healthcare Millennium MG, NC, and MyoSIGHT has a default password of (1) root.genie for the root user, (2) "service." for the service user, (3) admin.genie for the admin user, (4) reboot for the reboot user, and (5) shutdown for the shutdown user, which has unspecified impact and attack vectors.

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Gehealthcare -> Millennium mg 
Gehealthcare -> Millennium myosight 
Gehealthcare -> Millennium nc 
GE -> Healtcare millennium mg firmware 
GE -> Healtcare millennium myosight firmware 
GE -> Healtcare millennium nc firmware 
GE -> Healthcare millennium mg firmware 
GE -> Healthcare millennium myosight firmware 
GE -> Healthcare millennium nc firmware 

 References:
https://twitter.com/digitalbond/status/619250429751222277
http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/
http://apps.gehealthcare.com/servlet/ClientServlet/2354459-100.pdf?REQ=RAA&DIRECTION=2354459-100&FILENAME=2354459-100.pdf&FILEREV=4&DOCREV_ORG=4
http://apps.gehealthcare.com/servlet/ClientServlet/2338955-100.pdf?REQ=RAA&DIRECTION=2338955-100&FILENAME=2338955-100.pdf&FILEREV=1&DOCREV_ORG=1

Copyright 2024, cxsecurity.com

 

Back to Top