In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HGehealthcare Apexpro Telemetry Server
HWGehealthcareall versionsGehealthcare Apexpro Telemetry Server Firmware
OSGehealthcare≤ 4.2Gehealthcare Carescape Central Station Mai700
HWGehealthcareall versionsGehealthcare Carescape Central Station Mai700 Firmware
OSGehealthcare1.0Gehealthcare Carescape Central Station Mas700
HWGehealthcareall versionsGehealthcare Carescape Central Station Mas700 Firmware
OSGehealthcare1.0Gehealthcare Carescape Telemetry Server Mp100r
HWGehealthcareall versionsGehealthcare Carescape Telemetry Server Mp100r Firmware
OSGehealthcare≤ 4.2Gehealthcare Clinical Information Center Mp100d
HWGehealthcareall versionsGehealthcare Clinical Information Center Mp100d Firmware
OSGehealthcare4.05.0Gehealthcare Clinical Information Center Mp100r
HWGehealthcareall versionsGehealthcare Clinical Information Center Mp100r Firmware
OSGehealthcare4.05.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2020-6961CRITICAL10.0PL ✓same product
Ujawnienie klucza prywatnego SSH w produktach GE Healthcare
CVE-2020-6962CRITICAL10.0PL ✓same product
RCE poprzez brak walidacji danych wejściowych w GE Healthcare — systemy telemetryczne
CVE-2020-6965CRITICAL9.9PL ✓same product
GE Healthcare — nieautoryzowane przesyłanie plików przez mechanizm aktualizacji
CVE-2020-6966CRITICAL10.0PL ✓same product
Słabe szyfrowanie RDP umożliwia RCE w urządzeniach GE Healthcare
CVE-2020-6964HIGH8.6same product
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Informat...