9.8

CVE-2020-25175

GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GehealthcareImage Vault Firmware Version-
   GehealthcareImage Vault Version-
GehealthcareInnova 2000 Firmware Version-
   GehealthcareInnova 2000 Version-
GehealthcareInnova 3100 Firmware Version-
   GehealthcareInnova 3100 Version-
GehealthcareInnova 4100 Firmware Version-
   GehealthcareInnova 4100 Version-
GehealthcareOptima 320 Firmware Version-
   GehealthcareOptima 320 Version-
GehealthcareOptima 3100 Firmware Version-
   GehealthcareOptima 3100 Version-
GehealthcareBrivo Xr118 Firmware Version-
   GehealthcareBrivo Xr118 Version-
GehealthcareBrivo Xr383 Firmware Version-
   GehealthcareBrivo Xr383 Version-
GehealthcareBrivo Xr515 Firmware Version-
   GehealthcareBrivo Xr515 Version-
GehealthcareBrivo Xr575 Firmware Version-
   GehealthcareBrivo Xr575 Version-
GehealthcareAmx 700 Firmware Version-
   GehealthcareAmx 700 Version-
GehealthcareWdr1 Firmware Version-
   GehealthcareWdr1 Version-
GehealthcareSeno 200d Firmware Version-
   GehealthcareSeno 200d Version-
GehealthcareSeno Ds Firmware Version-
   GehealthcareSeno Ds Version-
GehealthcareBrivo Ct385 Firmware Version-
   GehealthcareBrivo Ct385 Version-
GehealthcareOptima Ct68 Firmware Version-
   GehealthcareOptima Ct68 Version-
GehealthcareInfinia Firmware Version-
   GehealthcareInfinia Version-
GehealthcareVentri Firmware Version-
   GehealthcareVentri Version-
GehealthcareXeleris Firmware Version-
   GehealthcareXeleris Version-
GehealthcarePetrace 800 Firmware Version-
   GehealthcarePetrace 800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.435
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

CWE-523 Unprotected Transport of Credentials

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.