HIGH · 10.0

CVE-2010-5308

GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Lo...

Vulnerability Description

GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen. NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
GehealthcareOptima Mr360 Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-5308?

CVE-2010-5308 is a vulnerability with a CVSS score of 10.0 (HIGH). GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Lo...

How severe is CVE-2010-5308?

CVE-2010-5308 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-5308?

Check the references section above for vendor advisories and patch information. Affected products include: Gehealthcare Optima Mr360 Firmware.