// For flags

CVE-2020-36547

GE Voluson S8 Service Browser hard-coded credentials

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change the configuration settings.

Se ha encontrado una vulnerabilidad en GE Voluson S8. Se ha calificado como crítica. Este problema afecta al navegador de servicios que produce credenciales embebidas. Atacar localmente es un requisito. Es recomendado cambiar los ajustes de configuración

*Credits: Marc Ruef/Rocco Gagliardi
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-06-16 CVE Reserved
  • 2022-06-17 CVE Published
  • 2024-01-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-798: Use of Hard-coded Credentials
CAPEC
References (2)
URL Tag Source
https://vuldb.com/?id.129833 X_refsource_misc
https://www.scip.ch/?news.20200701 X_refsource_misc
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ge
Search vendor "Ge"
Voluson S8 Firmware
Search vendor "Ge" for product "Voluson S8 Firmware"
--
Affected
in Ge
Search vendor "Ge"
Voluson S8
Search vendor "Ge" for product "Voluson S8"
--
Safe