10
CVSSv2

CVE-2020-6962

Published: 24/01/2020 Updated: 17/03/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an malicious user to obtain arbitrary remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gehealthcare apexpro_telemetry_server_firmware

gehealthcare apexpro_telemetry_server_firmware 4.3

gehealthcare carescape_b450_monitor_firmware 2.0

gehealthcare carescape_b650_monitor_firmware 1.0

gehealthcare carescape_b650_monitor_firmware 2.0

gehealthcare carescape_b850_monitor_firmware 1.0

gehealthcare carescape_b850_monitor_firmware 2.0

gehealthcare carescape_central_station_mai700_firmware 1.0

gehealthcare carescape_central_station_mai700_firmware 2.0

gehealthcare carescape_central_station_mas700_firmware 1.0

gehealthcare carescape_central_station_mas700_firmware 2.0

gehealthcare clinical_information_center_mp100d_firmware 4.0

gehealthcare clinical_information_center_mp100d_firmware 5.0

gehealthcare clinical_information_center_mp100r_firmware 4.0

gehealthcare clinical_information_center_mp100r_firmware 5.0

gehealthcare carescape_telemetry_server_mp100r_firmware

gehealthcare carescape_telemetry_server_mp100r_firmware 4.3