{"api_version":"1","generated_at":"2026-07-23T22:22:15+00:00","cve":"CVE-2010-5308","urls":{"html":"https://cve.report/CVE-2010-5308","api":"https://cve.report/api/cve/CVE-2010-5308.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-5308","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-5308"},"summary":{"title":"CVE-2010-5308","description":"GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen.  NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-08-04 14:59:11","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/","name":"http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Vulnerable Breasts And Brains? Cancer Scan Tech Has Terrible Password Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/digitalbond/status/619250429751222277","name":"https://twitter.com/digitalbond/status/619250429751222277","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Dale Peterson on Twitter: \"Funny slide with GE default password word cloud. Go bigguy! #Shakacon http://t.co/t1dcIziQza\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://apps.gehealthcare.com/servlet/ClientServlet/MR360+operator+manual+paper.pdf?REQ=RAA&DIRECTION=5339461-1EN&FILENAME=MR360%2Boperator%2Bmanual%2Bpaper.pdf&FILEREV=4&DOCREV_ORG=4","name":"http://apps.gehealthcare.com/servlet/ClientServlet/MR360+operator+manual+paper.pdf?REQ=RAA&DIRECTION=5339461-1EN&FILENAME=MR360%2Boperator%2Bmanual%2Bpaper.pdf&FILEREV=4&DOCREV_ORG=4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Marketplace-US Marketplace Home | GE Healthcare","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-5308","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-5308","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"5308","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"gehealthcare","cpe5":"optima_mr360_firmware","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:17:10.248Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://apps.gehealthcare.com/servlet/ClientServlet/MR360+operator+manual+paper.pdf?REQ=RAA&DIRECTION=5339461-1EN&FILENAME=MR360%2Boperator%2Bmanual%2Bpaper.pdf&FILEREV=4&DOCREV_ORG=4"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://twitter.com/digitalbond/status/619250429751222277"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-10-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen.  NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-08-04T09:57:02.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://apps.gehealthcare.com/servlet/ClientServlet/MR360+operator+manual+paper.pdf?REQ=RAA&DIRECTION=5339461-1EN&FILENAME=MR360%2Boperator%2Bmanual%2Bpaper.pdf&FILEREV=4&DOCREV_ORG=4"},{"tags":["x_refsource_MISC"],"url":"http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/"},{"tags":["x_refsource_MISC"],"url":"https://twitter.com/digitalbond/status/619250429751222277"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-5308","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen.  NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://apps.gehealthcare.com/servlet/ClientServlet/MR360+operator+manual+paper.pdf?REQ=RAA&DIRECTION=5339461-1EN&FILENAME=MR360%2Boperator%2Bmanual%2Bpaper.pdf&FILEREV=4&DOCREV_ORG=4","refsource":"CONFIRM","url":"http://apps.gehealthcare.com/servlet/ClientServlet/MR360+operator+manual+paper.pdf?REQ=RAA&DIRECTION=5339461-1EN&FILENAME=MR360%2Boperator%2Bmanual%2Bpaper.pdf&FILEREV=4&DOCREV_ORG=4"},{"name":"http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/","refsource":"MISC","url":"http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/"},{"name":"https://twitter.com/digitalbond/status/619250429751222277","refsource":"MISC","url":"https://twitter.com/digitalbond/status/619250429751222277"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-5308","datePublished":"2015-08-04T10:00:00.000Z","dateReserved":"2014-09-29T00:00:00.000Z","dateUpdated":"2024-08-07T04:17:10.248Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-08-04 14:59:11","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:gehealthcare:optima_mr360_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"F6056690-0318-4110-BF67-2F6B6455A1EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"5308","Ordinal":"1","Title":"CVE-2010-5308","CVE":"CVE-2010-5308","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"5308","Ordinal":"1","NoteData":"GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen.  NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default.","Type":"Description","Title":"CVE-2010-5308"},{"CveYear":"2010","CveId":"5308","Ordinal":"2","NoteData":"2015-08-04","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"5308","Ordinal":"3","NoteData":"2015-08-04","Type":"Other","Title":"Modified"}]}}}