GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
📦
discovery_xr656
Vendor: gehealthcare
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
1
Remote Access
Total CVEs
6
Total Indexed
Avg. EPSS
1.43%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
9.8
CVSS
Severity: CRITICAL
9.8
CVSS
CVE-2020-25175
RCE
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Severity: CRITICAL
10.0
CVSS
GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser user, and (3) #superxr for the root user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.
Severity: HIGH