Back to Database
Status published
Critical
CVE-2012-6693
GE Healthcare Centricity PACS 4.0 Server has a default password...
Vulnerability Description
GE Healthcare Centricity PACS 4.0 Server has a default password of (1) nasro for the nasro (ReadOnly) user and (2) nasrw for the nasrw (Read/Write) user, which has unspecified impact and attack vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6693
Credits & Attribution
No credits recorded in the NVD database.
References
- http://apps.gehealthcare.com/servlet/ClientServlet/C4x_SRV_SVC_2063464-001r2.pdf?REQ=RAA&DIRECTION=2063464-001&FILENAME=C4x_SRV_SVC_2063464-001r2.pdf&FILEREV=2&DOCREV_ORG=2
- http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/
- https://twitter.com/digitalbond/status/619250429751222277
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-037-02
- http://apps.gehealthcare.com/servlet/ClientServlet/C401_WS_INST_SV_2069560001r1.pdf?REQ=RAA&DIRECTION=2069560-001&FILENAME=C401_WS_INST_SV_2069560001r1.pdf&FILEREV=1&DOCREV_ORG=1
More from gehealthcare
View All →CVE-2014-9736
GE Healthcare Centricity Clinical Archive Audit Trail Repository has a...
Critical
10
CVE-2014-7233
GE Healthcare Precision THUNIS-800+ has a default password of (1)...
Critical
10
CVE-2014-7232
GE Healthcare Discovery XR656 and XR656 G2 has a password...
Critical
10
CVE-2013-7442
GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a...
Critical
10
CVE-2013-7405
The Ad Hoc Reporting feature in GE Healthcare Centricity DMS...
Critical
10
Affected Vendor
gehealthcare
View all reports →Affected Software
centricity pacs server
Vulnerable Versions:
4.0
Timeline
Official Publish:
August 4th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.