Researchers Uncover 11 Security Flaws in GE HealthCare Ultrasound Machines
ID: c8c9c2ca-1be3-5b1e-bc87-3a04ef3b3c64
STIX ID: report--c8c9c2ca-1be3-5b1e-bc87-3a04ef3b3c64
Feed Name: The Hacker News
Security researchers disclosed multiple critical vulnerabilities affecting GE HealthCare Vivid ultrasound devices (notably CVE-2024-27107, CVE-2024-1628 and CVE-2020-6977) and related software such as EchoPAC, which could allow attackers with physical access or internal network access to achieve administrative code execution, tamper with patient data, or install ransomware. The report includes an exploit chain using local access and USB attack vectors, and references other recent high-severity disclosures in medical and IoT products (Merge DICOM, Siemens EnMPro, ThroughTek Kalay). Vendors have issued advisories and mitigations, and updates are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
