CVE-2020-6964
Last modified
CVE-2020-6964 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.. EPSS estimates a 1.36% chance of exploitation in the next 30 days.
Description
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gehealthcare | Apexpro Telemetry Server Firmware | <= 4.2 |
| Gehealthcare | Carescape Central Station Mai700 Firmware | 1.0 |
| Gehealthcare | Carescape Central Station Mai700 Firmware | 2.0 |
| Gehealthcare | Carescape Central Station Mas700 Firmware | 1.0 |
| Gehealthcare | Carescape Central Station Mas700 Firmware | 2.0 |
| Gehealthcare | Clinical Information Center Mp100d Firmware | 4.0 |
| Gehealthcare | Clinical Information Center Mp100d Firmware | 5.0 |
| Gehealthcare | Clinical Information Center Mp100r Firmware | 4.0 |
| Gehealthcare | Clinical Information Center Mp100r Firmware | 5.0 |
| Gehealthcare | Carescape Telemetry Server Mp100r Firmware | <= 4.2 |
References
- https://www.us-cert.gov/ics/advisories/icsma-20-023-01Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-20-023-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6964?
How severe is CVE-2020-6964?
How do I fix CVE-2020-6964?
Are you affected by CVE-2020-6964?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
