CVE-2017-14002: Critical severity ge infinia hawkeye 4 firmware vulnerability
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14002?
CVE-2017-14002 is considered a critical vulnerability due to its potential for remote exploitation and unauthorized access.
How do I fix CVE-2017-14002?
To fix CVE-2017-14002, change the default or hard-coded credentials to strong, unique passwords.
What systems are affected by CVE-2017-14002?
CVE-2017-14002 affects all versions of GE Infinia and Infinia with Hawkeye 4 medical imaging systems.
What can an attacker do if they exploit CVE-2017-14002?
An attacker exploiting CVE-2017-14002 can bypass authentication and gain unauthorized access to the affected devices.
Is there a way to mitigate CVE-2017-14002?
Mitigation strategies for CVE-2017-14002 include implementing strong access controls and regularly updating credentials.