CVE-2020-6963
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD
Description
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Apexpro Telemetry Server | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Central Station Mai700 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Central Station Mas700 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Clinical Information Center Mp100d | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Clinical Information Center Mp100r | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Telemetry Server Mp100r | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-798
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
References (3)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: nvd@nist.gov
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.