CVE Database
/

CVE-2024-1486

Back to search

CVE-2024-1486

Published: May 14, 2024

Modified: Aug 16, 2024

PUBLISHED

CVSS v3.1

7.4

HIGH

Description

Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

VendorProductVersions

GE HealthCare

Venue

affected
R1
affected
R2
affected
R3 - <= R3.3
affected
R4 - <= R4.2

GE HealthCare

Venue Go

affected
R2
affected
R3 - <= R3.3
affected
R4 - <= R4.2

GE HealthCare

Venue Fit

affected
R3 - <= R3.3
affected
R4 - <= R4.2

GE HealthCare

LOGIQ e

affected
R7 - <= R9.1.4
affected
R8 - <= R10.1.3
affected
R9 - <= R11.0.2

GE HealthCare

LOGIQ He

affected
0 - <= R9.3.1

GE HealthCare

Vivid E

affected
E95 - < 206
affected
E90 - < 206
affected
E80 - < 206
affected
E9 113.2 - <= 113.2

GE HealthCare

Vivid S

affected
70N - < 206
affected
60N - < 206

GE HealthCare

Vivid T

affected
T8 - < 206
affected
T9 - < 206

GE HealthCare

Vivid iq

affected
0 - < 206

GE HealthCare

Invenia ABUS

affected
1.2.3

GE HealthCare

Invenia ABUS 2.0

affected
0 - < 2.2.9

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now