Back to Database
Status published
Critical
CVE-2024-27107
Weak account password in GE HealthCare EchoPAC products
Vulnerability Description
Weak account password in GE HealthCare EchoPAC products
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27107
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Andrea Palanca and Gabriele Quagliarella of Nozomi Networks
References
More from GE HealthCare
View All →CVE-2024-27110
Elevation of privilege vulnerability in GE HealthCare EchoPAC products
High
8.4
CVE-2024-27109
Insufficiently protected credentials in GE HealthCare EchoPAC products
High
7.6
CVE-2024-27108
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
Medium
6.8
CVE-2024-27106
Vulnerable data in transit in GE HealthCare EchoPAC products
Medium
5.7
CVE-2024-1630
Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component
High
7.7
Affected Vendor
GE HealthCare
View all reports →Affected Software
EchoPAC Software Only, ImageVault, EchoPAC Turnkey
Vulnerable Versions:
0
Timeline
Official Publish:
May 14th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H