CVE Vulnerabilities

CVE-2017-14006

Improper Authentication

Published: Mar 20, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Xeleris Ge 1.0 (including) 1.0 (including)
Xeleris Ge 1.1 (including) 1.1 (including)
Xeleris Ge 2.1 (including) 2.1 (including)
Xeleris Ge 3.0 (including) 3.0 (including)
Xeleris Ge 3.1 (including) 3.1 (including)

Potential Mitigations

References