6.5
CVSSv2

CVE-2020-6965

Published: 24/01/2020 Updated: 17/03/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software update mechanism allows an authenticated malicious user to upload arbitrary files on the system through a crafted update package.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gehealthcare apexpro_telemetry_server_firmware

gehealthcare carescape_b450_monitor_firmware 2.0

gehealthcare carescape_b650_monitor_firmware 1.0

gehealthcare carescape_b650_monitor_firmware 2.0

gehealthcare carescape_b850_monitor_firmware 1.0

gehealthcare carescape_b850_monitor_firmware 2.0

gehealthcare carescape_central_station_mai700_firmware 1.0

gehealthcare carescape_central_station_mas700_firmware 1.0

gehealthcare clinical_information_center_mp100d_firmware 4.0

gehealthcare clinical_information_center_mp100d_firmware 5.0

gehealthcare clinical_information_center_mp100r_firmware 4.0

gehealthcare clinical_information_center_mp100r_firmware 5.0

gehealthcare carescape_telemetry_server_mp100r_firmware