logo

Researchers Uncover 11 Security Flaws in GE HealthCare Ultrasound Machines

ID: c8c9c2ca-1be3-5b1e-bc87-3a04ef3b3c64

STIX ID: report--c8c9c2ca-1be3-5b1e-bc87-3a04ef3b3c64

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-16

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Security researchers disclosed multiple critical vulnerabilities affecting GE HealthCare Vivid ultrasound devices (notably CVE-2024-27107, CVE-2024-1628 and CVE-2020-6977) and related software such as EchoPAC, which could allow attackers with physical access or internal network access to achieve administrative code execution, tamper with patient data, or install ransomware. The report includes an exploit chain using local access and USB attack vectors, and references other recent high-severity disclosures in medical and IoT products (Merge DICOM, Siemens EnMPro, ThroughTek Kalay). Vendors have issued advisories and mitigations, and updates are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.