Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · gehealthcare

gehealthcare

· 7 Critical

Total CVEs

34

Critical

7

Products

266

Search All CVEs →

34

Products (266)

apexpro telemetry server6 CVEscarescape central station mai7006 CVEscarescape central station mai700 firmware6 CVEscarescape central station mas7006 CVEscarescape central station mas700 firmware6 CVEscarescape telemetry server mp100r6 CVEscarescape telemetry server mp100r firmware6 CVEsclinical information center mp100r6 CVEsclinical information center mp100d firmware6 CVEsclinical information center mp100d6 CVEsapexpro telemetry server firmware6 CVEsclinical information center mp100r firmware6 CVEsoptima mr360 firmware4 CVEsdiscovery nm 750b3 CVEscentricity pacs workstation3 CVEsdiscovery xr6563 CVEsoptima ct520 firmware3 CVEsoptima ct540 firmware3 CVEsbrivo ct3852 CVEsbrivo ct385 firmware2 CVEsbrivo definiu2 CVEsbrivo definiu firmware2 CVEsbrivo nm 6152 CVEsbrivo nm 615 firmware2 CVEsbrivo xr1182 CVEsbrivo xr118 firmware2 CVEsbrivo xr3832 CVEsbrivo xr383 firmware2 CVEsbrivo xr5152 CVEsbrivo xr515 firmware2 CVEsbrivo xr5752 CVEsbrivo xr575 firmware2 CVEscarescape b450 monitor2 CVEscarescape b450 monitor firmware2 CVEscarescape b650 monitor2 CVEscarescape b650 monitor firmware2 CVEscarescape b850 monitor2 CVEscarescape b850 monitor firmware2 CVEscentricity pacs-iw2 CVEscentricity pacs server2 CVEsxeleris firmware2 CVEs1.5t brivo mr355 firmware2 CVEs3.0t signa hd 162 CVEs3.0t signa hd 16 firmware2 CVEs3.0t signa hd 232 CVEs3.0t signa hd 23 firmware2 CVEs3.0t signa hdxt2 CVEs3.0t signa hdxt firmware2 CVEsamx 7002 CVEsamx 700 firmware2 CVEsbrightspeed edge2 CVEsbrightspeed edge firmware2 CVEsbrightspeed edge select2 CVEsbrightspeed edge select firmware2 CVEsbrightspeed elite2 CVEsbrightspeed elite firmware2 CVEsbrightspeed elite select2 CVEsbrightspeed elite select firmware2 CVEssenographe pristina firmware2 CVEssigna hdi 1.5t2 CVEssigna hdi 1.5t firmware2 CVEssigna vibrant2 CVEssigna vibrant firmware2 CVEsventri2 CVEsventri firmware2 CVEsvivid 7 bt022 CVEsvivid 7 bt02 firmware2 CVEsvivid 7 bt062 CVEsvivid 7 bt06 firmware2 CVEsvivid i bt062 CVEsvivid i bt06 firmware2 CVEsvoluson 730 bt052 CVEsvoluson 730 bt05 firmware2 CVEsvoluson 730 bt082 CVEsvoluson 730 bt08 firmware2 CVEswdr12 CVEswdr1 firmware2 CVEsxeleris2 CVEs1.5t brivo mr3552 CVEsdefinium 50002 CVEsdefinium 5000 firmware2 CVEsdefinium 60002 CVEsdefinium 6000 firmware2 CVEsdefinium 80002 CVEsdefinium 8000 firmware2 CVEsdiscovery ct590rt2 CVEsdiscovery ct590rt firmware2 CVEsdiscovery ct750hd2 CVEsdiscovery ct750hd firmware2 CVEsdiscovery iq2 CVEsdiscovery iq firmware2 CVEsdiscovery mi mi dr2 CVEsdiscovery mi mi dr firmware2 CVEsdiscovery nm8302 CVEsdiscovery nm830 firmware2 CVEsdiscovery nm\/ct8502 CVEsdiscovery nm\/ct850 firmware2 CVEsdiscovery nm\/ct 6702 CVEsdiscovery nm\/ct 670 firmware2 CVEsdiscovery nm\/ct 8602 CVEsdiscovery nm\/ct 860 firmware2 CVEsdiscovery nm\/ct 8702 CVEsdiscovery nm\/ct 870 firmware2 CVEsdiscovery nm\/ct d570c2 CVEsdiscovery nm\/ct d570c firmware2 CVEsdiscovery nm 6302 CVEsdiscovery nm 630 firmware2 CVEsdiscovery nm 750b firmware2 CVEsdiscovery nm d530c2 CVEsdiscovery nm d530c firmware2 CVEsdiscovery xr6502 CVEsdiscovery xr650 firmware2 CVEsdiscovery xr656\+2 CVEsdiscovery xr656\+ firmware2 CVEsdiscovery xr656 firmware2 CVEsechopac bt062 CVEsechopac bt06 firmware2 CVEsimage vault2 CVEsimage vault firmware2 CVEsinfinia2 CVEsinfinia firmware2 CVEsinnova 20002 CVEsinnova 2000 firmware2 CVEsinnova 2100-iq2 CVEsinnova 2100-iq firmware2 CVEsinnova 212-iq2 CVEsinnova 212-iq firmware2 CVEsinnova 31002 CVEsinnova 3100-iq2 CVEsinnova 3100-iq firmware2 CVEsinnova 3100 firmware2 CVEsinnova 313-iq2 CVEsinnova 313-iq firmware2 CVEsinnova 41002 CVEsinnova 4100-iq2 CVEsinnova 4100-iq firmware2 CVEsinnova 4100 firmware2 CVEsinnova igs 5202 CVEsinnova igs 520 firmware2 CVEsinnova igs 5302 CVEsinnova igs 530 firmware2 CVEsinnova igs 6202 CVEsinnova igs 620 firmware2 CVEsinnova igs 6302 CVEsinnova igs 630 firmware2 CVEsinnova igs 7302 CVEsinnova igs 730 firmware2 CVEslightspeed pro162 CVEslightspeed pro16 firmware2 CVEslightspeed rt162 CVEslightspeed rt16 firmware2 CVEslightspeed vct2 CVEslightspeed vct firmware2 CVEslogiq 5 bt032 CVEslogiq 5 bt03 firmware2 CVEslogiq 7 bt032 CVEslogiq 7 bt03 firmware2 CVEslogiq 7 bt042 CVEslogiq 7 bt04 firmware2 CVEslogiq 7 bt062 CVEslogiq 7 bt06 firmware2 CVEslogiq 9 bt022 CVEslogiq 9 bt02 firmware2 CVEslogiq 9 bt032 CVEslogiq 9 bt03 firmware2 CVEslogiq 9 bt042 CVEslogiq 9 bt04 firmware2 CVEslogiq 9 bt062 CVEslogiq 9 bt06 firmware2 CVEsoptima 31002 CVEsoptima 3100 firmware2 CVEsoptima 3202 CVEsoptima 320 firmware2 CVEsoptima advance2 CVEsoptima advance firmware2 CVEsoptima cl3202 CVEsoptima cl320 firmware2 CVEsoptima cl320i2 CVEsoptima cl320i firmware2 CVEsoptima cl323i2 CVEsoptima cl323i firmware2 CVEsoptima ct5202 CVEsoptima ct5402 CVEsoptima ct5802 CVEsoptima ct580 firmware2 CVEsoptima ct580rt2 CVEsoptima ct580rt firmware2 CVEsoptima ct580w2 CVEsoptima ct580w firmware2 CVEsoptima ct6602 CVEsoptima ct660 firmware2 CVEsoptima ct6702 CVEsoptima ct670 firmware2 CVEsoptima ct682 CVEsoptima ct68 firmware2 CVEsoptima expert \& professional2 CVEsoptima expert \& professional firmware2 CVEsoptima igs 3202 CVEsoptima igs 320 firmware2 CVEsoptima igs 3302 CVEsoptima igs 330 firmware2 CVEsoptima mr3602 CVEsoptima nm\/ct 6402 CVEsoptima nm\/ct 640 firmware2 CVEsoptima quantum2 CVEsoptima quantum firmware2 CVEsoptima xr200amx2 CVEsoptima xr200amx firmware2 CVEsoptima xr220amx2 CVEsoptima xr220amx firmware2 CVEsoptima xr6402 CVEsoptima xr640 firmware2 CVEsoptima xr6462 CVEsoptima xr646 firmware2 CVEspet discovery iq2 CVEspet discovery iq firmware2 CVEspet discovery iq upgrade2 CVEspet discovery iq upgrade firmware2 CVEspetrace 8002 CVEspetrace 800 firmware2 CVEsprecision 500d2 CVEsprecision 500d firmware2 CVEsrevolution act2 CVEsrevolution act firmware2 CVEsrevolution acts2 CVEsrevolution acts firmware2 CVEsrevolution ct2 CVEsrevolution ct firmware2 CVEsrevolution discovery ct2 CVEsrevolution discovery ct firmware2 CVEsrevolution evo2 CVEsrevolution evo firmware2 CVEsrevolution frontier2 CVEsrevolution frontier es2 CVEsrevolution frontier es firmware2 CVEsrevolution frontier firmware2 CVEsrevolution hd2 CVEsrevolution hd firmware2 CVEsseno 200d2 CVEsseno 200d firmware2 CVEsseno ds2 CVEsseno ds firmware2 CVEsseno essential2 CVEsseno essential firmware2 CVEssenographe pristina2 CVEscentricity image vault firmware1 CVEscadstream server firmware1 CVEsdiscovery xr656 g21 CVEsprecision thunis-800\+1 CVEscentricity clinical archive audit trail repository1 CVEsentegra p\&r1 CVEsmillennium mg1 CVEsdiscovery 530c firmware1 CVEsmillennium mg firmware1 CVEsmillennium myosight1 CVEsmillennium myosight firmware1 CVEscentricity dms firmware1 CVEsinfinia ii1 CVEsmillennium nc1 CVEsmillennium nc firmware1 CVEsdiscovery vh1 CVEsrevolution xq\/i1 CVEscentricity analytics server1 CVEscentricity dms1 CVEsprecision mpi1 CVEsoptima ct680 firmware1 CVEs

Recent Vulnerabilities

View all 34
CVE-2020-25179CRITICAL 9.8

GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

CVE-2020-25175CRITICAL 9.8

GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

CVE-2020-6966CRITICAL 10.0

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.

CVE-2020-6965CRITICAL 9.9

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software update mechanism allows an authenticated attacker to upload arbitrary files on the system through a crafted update package.

CVE-2020-6964HIGH 8.6

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.

CVE-2020-6963CRITICAL 10.0

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.

CVE-2020-6962CRITICAL 10.0

In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an attacker to obtain arbitrary remote code execution.

CVE-2020-6961CRITICAL 10.0

In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.

CVE-2014-9736

GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and attack vectors.

CVE-2014-7233

GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2) TH8740 for installation using TH8740_122_Setup.exe, (3) hrml for "Setup and Activation" using DSASetup, and (4) an empty string for Shutter Configuration, which has unspecified impact and attack vectors. NOTE: since these passwords appear to be used to access functionality during installation, this issue might not cross privilege boundaries and might not be a vulnerability.

CVE-2014-7232

GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser user, and (3) #superxr for the root user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2013-7442

GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator user and (2) iis for the IIS user, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.

CVE-2013-7405

The Ad Hoc Reporting feature in GE Healthcare Centricity DMS 4.2 has a password of Never!Mind for the Administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2013-7404

GE Healthcare Discovery NM 750b has a password of 2getin for the insite account for (1) Telnet and (2) FTP, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2012-6695

GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of ddpadmin for the ddpadmin user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2012-6694

GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1, and Server 4.0, has a password of 2charGE for the geservice account, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.

CVE-2012-6693

GE Healthcare Centricity PACS 4.0 Server has a default password of (1) nasro for the nasro (ReadOnly) user and (2) nasrw for the nasrw (Read/Write) user, which has unspecified impact and attack vectors.

CVE-2012-6660

GE Healthcare Precision MPi has a password of (1) orion for the serviceapp user, (2) orion for the clinical operator user, and (3) PlatinumOne for the administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2011-5324

The TeraRecon server, as used in GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions, has a password of (1) shared for the shared user and (2) scan for the scan user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2011-5323

GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2011-5322

GE Healthcare Centricity Analytics Server 1.1 has a default password of (1) V0yag3r for the SQL Server sa user, (2) G3car3s for the analyst user, (3) G3car3s for the ccg user, (4) V0yag3r for the viewer user, and (5) geservice for the geservice user in the Webmin interface, which has unspecified impact and attack vectors.

CVE-2010-5310

The Acquisition Workstation for the GE Healthcare Revolution XQ/i has a password of adw3.1 for the sdc user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2010-5309

GE Healthcare CADStream Server has a default password of confirma for the admin user, which has unspecified impact and attack vectors.

CVE-2010-5308

GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen. NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default.

CVE-2010-5307

The HIPAA configuration interface in GE Healthcare Optima MR360 has a password of (1) operator for the root account, (2) adw2.0 for the admin account, and (3) adw2.0 for the sdc account, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.