CVE-2020-6964
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 4.0
Source: NVD
Description
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Apexpro Telemetry Server | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Central Station Mai700 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Central Station Mas700 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Clinical Information Center Mp100d | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Clinical Information Center Mp100r | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.2 |
| Running on/with | Platform Versions |
|---|---|
Gehealthcare Carescape Telemetry Server Mp100r | All versions |
References (3)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: nvd@nist.gov
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.