CVE-2004-2777
Summary
| CVE | CVE-2004-2777 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-04 14:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value for the gemsservice account of the Ultrasound Database, and possibly (4) gemnet2002 for the gemnet2002 account of the GEMNet license server, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Gehealthcare | Centricity Image Vault Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerable Breasts And Brains? Cancer Scan Tech Has Terrible Password Security | af854a3a-2127-422b-91ae-364da2661108 | www.forbes.com | |
| Dale Peterson on Twitter: "Funny slide with GE default password word cloud. Go bigguy! #Shakacon http://t.co/t1dcIziQza" | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | |
| Marketplace-US Marketplace Home | GE Healthcare | af854a3a-2127-422b-91ae-364da2661108 | apps.gehealthcare.com | |
| GE Medical Devices Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.