GE Aestiva and Aespire Anesthesia CVE-2019-10966 Authentication Bypass Vulnerability
BID:109102
CVE-2019-10966 |Info
GE Aestiva and Aespire Anesthesia CVE-2019-10966 Authentication Bypass Vulnerability
| Bugtraq ID: | 109102 |
| Class: | Access Validation Error |
| CVE: |
CVE-2019-10966 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2019 12:00AM |
| Updated: | Jul 09 2019 12:00AM |
| Credit: | Elad Luz of CyberMDX |
| Vulnerable: |
GEHealthcare Aestiva 7900 GEHealthcare Aestiva 7100 GEHealthcare Aespire 7900 GEHealthcare Aespire 7100 |
| Not Vulnerable: | |
Discussion
GE Aestiva and Aespire Anesthesia CVE-2019-10966 Authentication Bypass Vulnerability
GE Aestiva and Aespire Anesthesia are prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may lead to further attacks.
The following versions of GE Aestiva and Aespire Anesthesia Machines are affected:
GE Aestiva and Aespire versions 7100
GE Aestiva and Aespire versions 7900
GE Aestiva and Aespire Anesthesia are prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may lead to further attacks.
The following versions of GE Aestiva and Aespire Anesthesia Machines are affected:
GE Aestiva and Aespire versions 7100
GE Aestiva and Aespire versions 7900
Solution / Fix
GE Aestiva and Aespire Anesthesia CVE-2019-10966 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GE Aestiva and Aespire Anesthesia CVE-2019-10966 Authentication Bypass Vulnerability
References:
References: