René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

87 lines
3.1 KiB
JSON

{
"id": "CVE-2010-5308",
"sourceIdentifier": "cve@mitre.org",
"published": "2015-08-04T14:59:11.503",
"lastModified": "2015-08-05T11:31:44.633",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen. NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default."
},
{
"lang": "es",
"value": "Vulnerabilidad en GE Healthcare Optima MR360, no requiere autenticaci\u00f3n para el procedimiento de acceso de emergencia de HIPAA, lo que permite a usuarios f\u00edsicamente pr\u00f3ximos obtener acceso a trav\u00e9s de un nombre de usuario arbitrario en la pantalla de Emergency Login. NOTA: esto podr\u00eda no calificarse para su incorporaci\u00f3n en CVE si el acceso de emergencia no autenticado es parte de la pol\u00edtica de seguridad prevista para el producto, puede ser controlado por el administrador del sistema y no est\u00e1 habilitado por defecto."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": true,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:gehealthcare:optima_mr360_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F6056690-0318-4110-BF67-2F6B6455A1EA"
}
]
}
]
}
],
"references": [
{
"url": "http://apps.gehealthcare.com/servlet/ClientServlet/MR360+operator+manual+paper.pdf?REQ=RAA&DIRECTION=5339461-1EN&FILENAME=MR360%2Boperator%2Bmanual%2Bpaper.pdf&FILEREV=4&DOCREV_ORG=4",
"source": "cve@mitre.org"
},
{
"url": "http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/",
"source": "cve@mitre.org"
},
{
"url": "https://twitter.com/digitalbond/status/619250429751222277",
"source": "cve@mitre.org"
}
]
}