ID

VAR-201508-0151


CVE

CVE-2013-7404


TITLE

GE Healthcare Discovery NM 750b Trust Management Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-05139 // CNNVD: CNNVD-201508-032

DESCRIPTION

GE Healthcare Discovery NM 750b has a password of 2getin for the insite account for (1) Telnet and (2) FTP, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. The GE Healthcare Discovery NM 750b is a high-end molecular mammography device for the medical industry at General Electric (GE). An attacker could exploit this vulnerability to control the device

Trust: 2.52

sources: NVD: CVE-2013-7404 // JVNDB: JVNDB-2015-004007 // CNVD: CNVD-2015-05139 // BID: 76168 // VULMON: CVE-2013-7404

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-05139

AFFECTED PRODUCTS

vendor:gehealthcaremodel:discovery nm 750bscope:eqversion:*

Trust: 1.0

vendor:ge healthcaremodel:discovery nm 750bscope: - version: -

Trust: 0.8

vendor:gemodel:discovery nm 750bscope: - version: -

Trust: 0.6

vendor:gehealthcaremodel:discovery nm 750bscope: - version: -

Trust: 0.6

vendor:gehealthcaremodel:discovery nm 750bscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2015-05139 // BID: 76168 // JVNDB: JVNDB-2015-004007 // CNNVD: CNNVD-201508-032 // NVD: CVE-2013-7404

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-7404
value: HIGH

Trust: 1.0

NVD: CVE-2013-7404
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-05139
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201508-032
value: CRITICAL

Trust: 0.6

VULMON: CVE-2013-7404
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-7404
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2015-05139
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-05139 // VULMON: CVE-2013-7404 // JVNDB: JVNDB-2015-004007 // CNNVD: CNNVD-201508-032 // NVD: CVE-2013-7404

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.8

sources: JVNDB: JVNDB-2015-004007 // NVD: CVE-2013-7404

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201508-032

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201508-032

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004007

PATCH

title:Discovery NM 750b Nuclear Medicine Imaging Systems Installation Manualurl:http://apps.gehealthcare.com/servlet/ClientServlet/5411136-1EN_r3.pdf?DOCCLASS=A&REQ=RAC&DIRECTION=5411136-1EN&FILENAME=5411136-1EN_r3.pdf&FILEREV=3&DOCREV_ORG=3&SUBMIT=+ACCEPT+

Trust: 0.8

sources: JVNDB: JVNDB-2015-004007

EXTERNAL IDS

db:NVDid:CVE-2013-7404

Trust: 3.4

db:ICS CERTid:ICSMA-18-037-02

Trust: 1.9

db:JVNDBid:JVNDB-2015-004007

Trust: 0.8

db:CNVDid:CNVD-2015-05139

Trust: 0.6

db:CNNVDid:CNNVD-201508-032

Trust: 0.6

db:BIDid:76168

Trust: 0.4

db:VULMONid:CVE-2013-7404

Trust: 0.1

sources: CNVD: CNVD-2015-05139 // VULMON: CVE-2013-7404 // BID: 76168 // JVNDB: JVNDB-2015-004007 // CNNVD: CNNVD-201508-032 // NVD: CVE-2013-7404

REFERENCES

url:http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/

Trust: 2.5

url:https://twitter.com/digitalbond/status/619250429751222277

Trust: 2.3

url:https://ics-cert.us-cert.gov/advisories/icsma-18-037-02

Trust: 2.0

url:http://apps.gehealthcare.com/servlet/clientservlet/5411136-1en_r3.pdf?req=raa&direction=5411136-1en&filename=5411136-1en_r3.pdf&filerev=3&docrev_org=3

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-7404

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-7404

Trust: 0.8

url:http://apps.gehealthcare.com/servlet/clientservlet/0908141_dms%204.2%20mtg.pdf?docclass=a&req=rac&direction=0908141&filename=0908141_dms+4.2+mtg.pdf&filerev=d&docrev_org=d&submit=+accept+

Trust: 0.3

url:http://www3.gehealthcare.com/en

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/255.html

Trust: 0.1

url:https://www.securityfocus.com/bid/76168

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2015-05139 // VULMON: CVE-2013-7404 // BID: 76168 // JVNDB: JVNDB-2015-004007 // CNNVD: CNNVD-201508-032 // NVD: CVE-2013-7404

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 76168

SOURCES

db:CNVDid:CNVD-2015-05139
db:VULMONid:CVE-2013-7404
db:BIDid:76168
db:JVNDBid:JVNDB-2015-004007
db:CNNVDid:CNNVD-201508-032
db:NVDid:CVE-2013-7404

LAST UPDATE DATE

2024-08-14T13:33:50.011000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-05139date:2015-08-06T00:00:00
db:VULMONid:CVE-2013-7404date:2018-03-28T00:00:00
db:BIDid:76168date:2015-08-04T00:00:00
db:JVNDBid:JVNDB-2015-004007date:2018-04-02T00:00:00
db:CNNVDid:CNNVD-201508-032date:2015-08-05T00:00:00
db:NVDid:CVE-2013-7404date:2018-03-28T01:29:02.340

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-05139date:2015-08-06T00:00:00
db:VULMONid:CVE-2013-7404date:2015-08-04T00:00:00
db:BIDid:76168date:2015-08-04T00:00:00
db:JVNDBid:JVNDB-2015-004007date:2015-08-06T00:00:00
db:CNNVDid:CNNVD-201508-032date:2015-08-05T00:00:00
db:NVDid:CVE-2013-7404date:2015-08-04T14:59:21.673