Vulnerability Details CVE-2020-6965
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software update mechanism allows an authenticated attacker to upload arbitrary files on the system through a crafted update package.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.7%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 6.5
Products affected by CVE-2020-6965
-
cpe:2.3:h:gehealthcare:apexpro_telemetry_server:-
-
cpe:2.3:h:gehealthcare:carescape_b450_monitor:-
-
cpe:2.3:h:gehealthcare:carescape_b650_monitor:-
-
cpe:2.3:h:gehealthcare:carescape_b850_monitor:-
-
cpe:2.3:h:gehealthcare:carescape_central_station_mai700:-
-
cpe:2.3:h:gehealthcare:carescape_central_station_mas700:-
-
cpe:2.3:h:gehealthcare:carescape_telemetry_server_mp100r:-
-
cpe:2.3:h:gehealthcare:clinical_information_center_mp100d:-
-
cpe:2.3:h:gehealthcare:clinical_information_center_mp100r:-
-
cpe:2.3:o:gehealthcare:apexpro_telemetry_server_firmware:3.9
-
cpe:2.3:o:gehealthcare:apexpro_telemetry_server_firmware:4.0
-
cpe:2.3:o:gehealthcare:apexpro_telemetry_server_firmware:4.1
-
cpe:2.3:o:gehealthcare:apexpro_telemetry_server_firmware:4.2
-
cpe:2.3:o:gehealthcare:carescape_b450_monitor_firmware:2.0
-
cpe:2.3:o:gehealthcare:carescape_b650_monitor_firmware:1.0
-
cpe:2.3:o:gehealthcare:carescape_b650_monitor_firmware:2.0
-
cpe:2.3:o:gehealthcare:carescape_b850_monitor_firmware:1.0
-
cpe:2.3:o:gehealthcare:carescape_b850_monitor_firmware:2.0
-
cpe:2.3:o:gehealthcare:carescape_central_station_mai700_firmware:1.0
-
cpe:2.3:o:gehealthcare:carescape_central_station_mas700_firmware:1.0
-
cpe:2.3:o:gehealthcare:carescape_telemetry_server_mp100r_firmware:4.2
-
cpe:2.3:o:gehealthcare:clinical_information_center_mp100d_firmware:4.0
-
cpe:2.3:o:gehealthcare:clinical_information_center_mp100d_firmware:5.0
-
cpe:2.3:o:gehealthcare:clinical_information_center_mp100r_firmware:4.0
-
cpe:2.3:o:gehealthcare:clinical_information_center_mp100r_firmware:5.0