In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:NGehealthcare Apexpro Telemetry Server
HWGehealthcarewszystkie wersjeGehealthcare Apexpro Telemetry Server Firmware
OSGehealthcare≤ 4.2Gehealthcare Carescape Central Station Mai700
HWGehealthcarewszystkie wersjeGehealthcare Carescape Central Station Mai700 Firmware
OSGehealthcare1.02.0Gehealthcare Carescape Central Station Mas700
HWGehealthcarewszystkie wersjeGehealthcare Carescape Central Station Mas700 Firmware
OSGehealthcare1.02.0Gehealthcare Carescape Telemetry Server Mp100r
HWGehealthcarewszystkie wersjeGehealthcare Carescape Telemetry Server Mp100r Firmware
OSGehealthcare≤ 4.2Gehealthcare Clinical Information Center Mp100d
HWGehealthcarewszystkie wersjeGehealthcare Clinical Information Center Mp100d Firmware
OSGehealthcare4.05.0Gehealthcare Clinical Information Center Mp100r
HWGehealthcarewszystkie wersjeGehealthcare Clinical Information Center Mp100r Firmware
OSGehealthcare4.05.0
Powiązane podatności
Ujawnienie klucza prywatnego SSH w produktach GE Healthcare
RCE poprzez brak walidacji danych wejściowych w GE Healthcare — systemy telemetryczne
GE Healthcare: zakodowane dane SMB umożliwiające RCE
GE Healthcare — nieautoryzowane przesyłanie plików przez mechanizm aktualizacji
Słabe szyfrowanie RDP umożliwia RCE w urządzeniach GE Healthcare