CVE-2013-7442: Critical severity Gehealthcare Centricity Pacs Workstation vulnerability

Published Aug 4, 2015
·
Updated

GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator user and (2) iis for the IIS user, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.

Affected Software

2 affected components
Gehealthcare Centricity Pacs Workstation=4.0
Gehealthcare Centricity Pacs Workstation=4.0.1

Event History

Aug 4, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2013-7442?

The severity of CVE-2013-7442 is currently unspecified, but it relates to hardcoded passwords in GE Healthcare Centricity PACS Workstation.

2

How do I fix CVE-2013-7442?

To fix CVE-2013-7442, you should change the default passwords for the Administrator and IIS users in the Centricity PACS Workstation.

3

What software versions are affected by CVE-2013-7442?

CVE-2013-7442 affects GE Healthcare Centricity PACS Workstation versions 4.0 and 4.0.1.

4

What impact could CVE-2013-7442 have on security?

CVE-2013-7442 could potentially allow unauthorized access to sensitive patient data due to weak passwords.

5

What types of attacks are associated with CVE-2013-7442?

CVE-2013-7442 is related to unspecified attack vectors involving the weak passwords of Administrator and IIS user accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203