ID

VAR-201508-0275


CVE

CVE-2013-7442


TITLE

GE Healthcare Centricity PACS Workstation Trust Management Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-05137 // CNNVD: CNNVD-201508-034

DESCRIPTION

GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator user and (2) iis for the IIS user, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it. (1) For admin users CANal1 password (2) IIS For users iis password It is unknown whether this password is default, hard-coded, or dependent on other systems or products that require a fixed value.It may be subject to unspecified effects and attacks. An attacker could use this vulnerability to control the device. Attackers can exploit this issue to bypass the authentication mechanism and gain access to the vulnerable device

Trust: 2.79

sources: NVD: CVE-2013-7442 // JVNDB: JVNDB-2015-004009 // CNVD: CNVD-2015-05137 // BID: 76178 // BID: 76169 // VULMON: CVE-2013-7442

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-05137

AFFECTED PRODUCTS

vendor:gehealthcaremodel:centricity pacs workstationscope:eqversion:4.0.1

Trust: 2.2

vendor:gehealthcaremodel:centricity pacs workstationscope:eqversion:4.0

Trust: 2.2

vendor:ge healthcaremodel:centricity pacsscope:eqversion:4.0

Trust: 0.8

vendor:ge healthcaremodel:centricity pacsscope:eqversion:4.0.1

Trust: 0.8

vendor:gemodel:centricity pacs workstationscope:eqversion:4.0

Trust: 0.6

vendor:gemodel:centricity pacs workstationscope:eqversion:4.0.1

Trust: 0.6

sources: CNVD: CNVD-2015-05137 // BID: 76178 // BID: 76169 // JVNDB: JVNDB-2015-004009 // CNNVD: CNNVD-201508-034 // NVD: CVE-2013-7442

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-7442
value: HIGH

Trust: 1.0

NVD: CVE-2013-7442
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-05137
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201508-034
value: CRITICAL

Trust: 0.6

VULMON: CVE-2013-7442
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-7442
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2015-05137
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-05137 // VULMON: CVE-2013-7442 // JVNDB: JVNDB-2015-004009 // CNNVD: CNNVD-201508-034 // NVD: CVE-2013-7442

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.8

sources: JVNDB: JVNDB-2015-004009 // NVD: CVE-2013-7442

THREAT TYPE

network

Trust: 0.6

sources: BID: 76178 // BID: 76169

TYPE

Design Error

Trust: 0.6

sources: BID: 76178 // BID: 76169

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004009

PATCH

title:Centricity PACS Workstation Installation and Service Manual (PACS 4.0 Release)url:http://apps.gehealthcare.com/servlet/ClientServlet/C40_WS_INST_SV_2063534-001r2.pdf?REQ=RAA&DIRECTION=2063534-001&FILENAME=C40_WS_INST_SV_2063534-001r2.pdf&FILEREV=1&DOCREV_ORG=1

Trust: 0.8

title:Centricity PACS Workstation Installation and Service Manual (PACS 4.0.1 Release)url:http://apps.gehealthcare.com/servlet/ClientServlet/C401_WS_INST_SV_2069560001r1.pdf?REQ=RAA&DIRECTION=2069560-001&FILENAME=C401_WS_INST_SV_2069560001r1.pdf&FILEREV=1&DOCREV_ORG=1

Trust: 0.8

sources: JVNDB: JVNDB-2015-004009

EXTERNAL IDS

db:NVDid:CVE-2013-7442

Trust: 3.7

db:ICS CERTid:ICSMA-18-037-02

Trust: 1.9

db:BIDid:76169

Trust: 1.0

db:JVNDBid:JVNDB-2015-004009

Trust: 0.8

db:CNVDid:CNVD-2015-05137

Trust: 0.6

db:CNNVDid:CNNVD-201508-034

Trust: 0.6

db:BIDid:76178

Trust: 0.3

db:VULMONid:CVE-2013-7442

Trust: 0.1

sources: CNVD: CNVD-2015-05137 // VULMON: CVE-2013-7442 // BID: 76178 // BID: 76169 // JVNDB: JVNDB-2015-004009 // CNNVD: CNNVD-201508-034 // NVD: CVE-2013-7442

REFERENCES

url:http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/

Trust: 3.7

url:https://ics-cert.us-cert.gov/advisories/icsma-18-037-02

Trust: 2.0

url:http://apps.gehealthcare.com/servlet/clientservlet/c401_ws_inst_sv_2069560001r1.pdf?req=raa&direction=2069560-001&filename=c401_ws_inst_sv_2069560001r1.pdf&filerev=1&docrev_org=1

Trust: 1.4

url:http://www3.gehealthcare.com/en

Trust: 1.2

url:https://twitter.com/digitalbond/status/619250429751222277

Trust: 1.1

url:http://apps.gehealthcare.com/servlet/clientservlet/c40_ws_inst_sv_2063534-001r2.pdf?req=raa&direction=2063534-001&filename=c40_ws_inst_sv_2063534-001r2.pdf&filerev=1&docrev_org=1

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-7442

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-7442

Trust: 0.8

url:https://www.securityfocus.com/bid/76169

Trust: 0.7

url:https://cwe.mitre.org/data/definitions/255.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2015-05137 // VULMON: CVE-2013-7442 // BID: 76178 // BID: 76169 // JVNDB: JVNDB-2015-004009 // CNNVD: CNNVD-201508-034 // NVD: CVE-2013-7442

CREDITS

Scott Erven

Trust: 1.2

sources: BID: 76178 // BID: 76169 // CNNVD: CNNVD-201508-034

SOURCES

db:CNVDid:CNVD-2015-05137
db:VULMONid:CVE-2013-7442
db:BIDid:76178
db:BIDid:76169
db:JVNDBid:JVNDB-2015-004009
db:CNNVDid:CNNVD-201508-034
db:NVDid:CVE-2013-7442

LAST UPDATE DATE

2024-08-14T13:33:49.877000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-05137date:2019-11-01T00:00:00
db:VULMONid:CVE-2013-7442date:2018-03-28T00:00:00
db:BIDid:76178date:2015-08-04T00:00:00
db:BIDid:76169date:2019-04-12T17:00:00
db:JVNDBid:JVNDB-2015-004009date:2018-04-02T00:00:00
db:CNNVDid:CNNVD-201508-034date:2019-04-15T00:00:00
db:NVDid:CVE-2013-7442date:2018-03-28T01:29:02.450

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-05137date:2015-08-06T00:00:00
db:VULMONid:CVE-2013-7442date:2015-08-04T00:00:00
db:BIDid:76178date:2015-08-04T00:00:00
db:BIDid:76169date:2015-08-04T00:00:00
db:JVNDBid:JVNDB-2015-004009date:2015-08-06T00:00:00
db:CNNVDid:CNNVD-201508-034date:2015-08-05T00:00:00
db:NVDid:CVE-2013-7442date:2015-08-04T14:59:23.657