← Back

CVE-2020-6963

nvd nist
Published: Jan 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD

Description

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.

Affected (8)

Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2
Running on/withPlatform Versions
Gehealthcare
Apexpro Telemetry Server
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0
Running on/withPlatform Versions
Gehealthcare
Carescape Central Station Mai700
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0
Running on/withPlatform Versions
Gehealthcare
Carescape Central Station Mas700
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Gehealthcare
Version 4.0
Version 5.0
Running on/withPlatform Versions
Gehealthcare
Clinical Information Center Mp100d
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Gehealthcare
Version 4.0
Version 5.0
Running on/withPlatform Versions
Gehealthcare
Clinical Information Center Mp100r
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2
Running on/withPlatform Versions
Gehealthcare
Carescape Telemetry Server Mp100r
All versions

References (3)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.