logo

GE Ultrasound Gear Riddled With Bugs, Open to Ransomware & Data Theft

ID: 8f4a1ec8-a78f-52d4-8496-beab1996a1bc

STIX ID: report--8f4a1ec8-a78f-52d4-8496-beab1996a1bc

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-05-16

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers reported 11 vulnerabilities in GE HealthCare Vivid Ultrasound devices and related software (Common Service Desktop Web and EchoPAC) — including hardcoded credentials, command injection, and missing encryption — with severities up to CVSS 9.6; these flaws can enable administrative takeover, patient-data exposure, or ransomware deployment, though many attack paths require physical access while EchoPAC can be abused from the local network. GE HealthCare has published patches and mitigations on its product security portal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.