CVE-2020-25179
CRITICALCVSS 9.8/10EPSS 1.35%
Last modified
CVE-2020-25179 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gehealthcare | 3.0t Signa Hdxt Firmware | All versions |
| Gehealthcare | 3.0t Signa Hd 16 Firmware | All versions |
| Gehealthcare | 3.0t Signa Hd 23 Firmware | All versions |
| Gehealthcare | 1.5t Brivo Mr355 Firmware | All versions |
| Gehealthcare | Optima Mr360 Firmware | All versions |
| Gehealthcare | Signa Hdi 1.5t Firmware | All versions |
| Gehealthcare | Signa Vibrant Firmware | All versions |
| Gehealthcare | Logiq 5 Bt03 Firmware | All versions |
| Gehealthcare | Logiq 7 Bt03 Firmware | All versions |
| Gehealthcare | Logiq 7 Bt04 Firmware | All versions |
| Gehealthcare | Logiq 7 Bt06 Firmware | All versions |
| Gehealthcare | Logiq 9 Bt02 Firmware | All versions |
| Gehealthcare | Logiq 9 Bt03 Firmware | All versions |
| Gehealthcare | Logiq 9 Bt04 Firmware | All versions |
| Gehealthcare | Logiq 9 Bt06 Firmware | All versions |
| Gehealthcare | Vivid I Bt06 Firmware | All versions |
| Gehealthcare | Vivid 7 Bt02 Firmware | All versions |
| Gehealthcare | Vivid 7 Bt06 Firmware | All versions |
| Gehealthcare | Echopac Bt06 Firmware | All versions |
| Gehealthcare | Image Vault Firmware | All versions |
| Gehealthcare | Voluson 730 Bt05 Firmware | All versions |
| Gehealthcare | Voluson 730 Bt08 Firmware | All versions |
| Gehealthcare | Innova 2000 Firmware | All versions |
| Gehealthcare | Innova 3100 Firmware | All versions |
| Gehealthcare | Innova 4100 Firmware | All versions |
| Gehealthcare | Innova 2100-Iq Firmware | All versions |
| Gehealthcare | Innova 3100-Iq Firmware | All versions |
| Gehealthcare | Innova 4100-Iq Firmware | All versions |
| Gehealthcare | Innova 212-Iq Firmware | All versions |
| Gehealthcare | Innova 313-Iq Firmware | All versions |
| Gehealthcare | Optima 320 Firmware | All versions |
| Gehealthcare | Optima Cl320i Firmware | All versions |
| Gehealthcare | Optima Cl323i Firmware | All versions |
| Gehealthcare | Optima Cl320 Firmware | All versions |
| Gehealthcare | Optima 3100 Firmware | All versions |
| Gehealthcare | Optima Igs 320 Firmware | All versions |
| Gehealthcare | Optima Igs 330 Firmware | All versions |
| Gehealthcare | Innova Igs 520 Firmware | All versions |
| Gehealthcare | Innova Igs 530 Firmware | All versions |
| Gehealthcare | Innova Igs 620 Firmware | All versions |
| Gehealthcare | Innova Igs 630 Firmware | All versions |
| Gehealthcare | Innova Igs 730 Firmware | All versions |
| Gehealthcare | Brivo Xr118 Firmware | All versions |
| Gehealthcare | Brivo Xr383 Firmware | All versions |
| Gehealthcare | Brivo Xr515 Firmware | All versions |
| Gehealthcare | Brivo Xr575 Firmware | All versions |
| Gehealthcare | Brivo Definiu Firmware | All versions |
| Gehealthcare | Definium 5000 Firmware | All versions |
| Gehealthcare | Definium 6000 Firmware | All versions |
| Gehealthcare | Definium 8000 Firmware | All versions |
Showing 50 of 112 affected configurations. See NVD for the full list.
References
- https://us-cert.cisa.gov/ics/advisories/icsma-20-343-01Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsma-20-343-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25179?
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
How severe is CVE-2020-25179?
CVE-2020-25179 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.35% probability of exploitation in the next 30 days.
How do I fix CVE-2020-25179?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-25173An attacker with local network access can obtain a fixed cry…7.8
- CVE-2020-25174A DLL hijacking vulnerability in the B. Braun OnlineSuite Ve…7.8
- CVE-2020-25175GE Healthcare Imaging and Ultrasound Products may allow spec…9.8
- CVE-2020-25176Some commands used by the Rockwell Automation ISaGRAF Runtim…9.8
- CVE-2020-25177WECON PLC Editor Versions 1.3.8 and prior has a stack-based …8.8
- CVE-2020-25178ISaGRAF Workbench communicates with Rockwell Automation ISaG…8.8
- CVE-2020-2518Vulnerability in the Java VM component of Oracle Database Se…7.5
- CVE-2020-25180Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x inc…6.5
- CVE-2020-25181WECON PLC Editor Versions 1.3.8 and prior has a heap-based b…8.8
- CVE-2020-25182Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x sea…6.7
- CVE-2020-25183Medtronic MyCareLink Smart 25000 contains an authenticatio…8.8
- CVE-2020-25184Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x sto…5.5
Are you affected by CVE-2020-25179?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
