Back to Database
Status published
High
CVE-2024-1486
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
Vulnerability Description
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1486
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Andrea Palanca and Gabriele Quagliarella of Nozomi Networks
References
More from GE HealthCare
View All →CVE-2024-27110
Elevation of privilege vulnerability in GE HealthCare EchoPAC products
High
8.4
CVE-2024-27109
Insufficiently protected credentials in GE HealthCare EchoPAC products
High
7.6
CVE-2024-27108
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
Medium
6.8
CVE-2024-27107
Weak account password in GE HealthCare EchoPAC products
Critical
9.6
CVE-2024-27106
Vulnerable data in transit in GE HealthCare EchoPAC products
Medium
5.7
Affected Vendor
GE HealthCare
View all reports →Affected Software
Venue, Venue Go, Venue Fit, LOGIQ e, LOGIQ He, Vivid E, Vivid S, Vivid T, Vivid iq, Invenia ABUS, Invenia ABUS 2.0
Vulnerable Versions:
R1, R2, R3, R4, R7, R8, R9, 0, E95, E90, E80, E9 113.2, 70N, 60N, T8, T9, 1.2.3
Timeline
Official Publish:
May 14th, 2024
Last Modified:
August 16th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H