cbcvebase.
CVE-2020-6962
published 2020-01-24

CVE-2020-6962: In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE…

PriorityP268critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
4.93%
91.0th percentile
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an attacker to obtain arbitrary remote code execution.

Affected

17 ranges
VendorProductVersion rangeFixed in
gehealthcareapexpro_telemetry_server_firmware<= 4.2
gehealthcareapexpro_telemetry_server_firmware
gehealthcarecarescape_b450_monitor_firmware
gehealthcarecarescape_b650_monitor_firmware
gehealthcarecarescape_b650_monitor_firmware
gehealthcarecarescape_b850_monitor_firmware
gehealthcarecarescape_b850_monitor_firmware
gehealthcarecarescape_central_station_mai700_firmware
gehealthcarecarescape_central_station_mai700_firmware
gehealthcarecarescape_central_station_mas700_firmware
gehealthcarecarescape_central_station_mas700_firmware
gehealthcarecarescape_telemetry_server_mp100r_firmware<= 4.2
gehealthcarecarescape_telemetry_server_mp100r_firmware
gehealthcareclinical_information_center_mp100d_firmware
gehealthcareclinical_information_center_mp100d_firmware
gehealthcareclinical_information_center_mp100r_firmware
gehealthcareclinical_information_center_mp100r_firmware

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.