9.8

CVE-2020-25179

GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GehealthcareImage Vault Firmware Version-
   GehealthcareImage Vault Version-
GehealthcareInnova 2000 Firmware Version-
   GehealthcareInnova 2000 Version-
GehealthcareInnova 3100 Firmware Version-
   GehealthcareInnova 3100 Version-
GehealthcareInnova 4100 Firmware Version-
   GehealthcareInnova 4100 Version-
GehealthcareOptima 320 Firmware Version-
   GehealthcareOptima 320 Version-
GehealthcareOptima 3100 Firmware Version-
   GehealthcareOptima 3100 Version-
GehealthcareBrivo Xr118 Firmware Version-
   GehealthcareBrivo Xr118 Version-
GehealthcareBrivo Xr383 Firmware Version-
   GehealthcareBrivo Xr383 Version-
GehealthcareBrivo Xr515 Firmware Version-
   GehealthcareBrivo Xr515 Version-
GehealthcareBrivo Xr575 Firmware Version-
   GehealthcareBrivo Xr575 Version-
GehealthcareAmx 700 Firmware Version-
   GehealthcareAmx 700 Version-
GehealthcareWdr1 Firmware Version-
   GehealthcareWdr1 Version-
GehealthcareSeno 200d Firmware Version-
   GehealthcareSeno 200d Version-
GehealthcareSeno Ds Firmware Version-
   GehealthcareSeno Ds Version-
GehealthcareBrivo Ct385 Firmware Version-
   GehealthcareBrivo Ct385 Version-
GehealthcareOptima Ct68 Firmware Version-
   GehealthcareOptima Ct68 Version-
GehealthcareInfinia Firmware Version-
   GehealthcareInfinia Version-
GehealthcareVentri Firmware Version-
   GehealthcareVentri Version-
GehealthcareXeleris Firmware Version-
   GehealthcareXeleris Version-
GehealthcarePetrace 800 Firmware Version-
   GehealthcarePetrace 800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.447
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.