CVE-2020-6962
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD
Description
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an attacker to obtain arbitrary remote code execution.
Affected (17)
Products: Gehealthcare: Apexpro Telemetry Server Firmware, Carescape B450 Monitor Firmware, Carescape B650 Monitor Firmware, Carescape B850 Monitor Firmware, Carescape Central Station Mai700 Firmware, Carescape Central Station Mas700 Firmware, Clinical Information Center Mp100d Firmware, Clinical Information Center Mp100r Firmware, Carescape Telemetry Server Mp100r Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Apexpro Telemetry Server | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape B450 Monitor | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape B650 Monitor | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape B850 Monitor | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Central Station Mai700 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Central Station Mas700 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Clinical Information Center Mp100d | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Clinical Information Center Mp100r | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Telemetry Server Mp100r | All versions |
References (3)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: nvd@nist.gov
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.