890
VMScore

CVE-2020-6966

Published: 24/01/2020 Updated: 17/03/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an malicious user to obtain remote code execution of devices on the network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gehealthcare apexpro_telemetry_server_firmware

gehealthcare carescape_central_station_mai700_firmware 1.0

gehealthcare carescape_central_station_mas700_firmware 1.0

gehealthcare clinical_information_center_mp100d_firmware 4.0

gehealthcare clinical_information_center_mp100d_firmware 5.0

gehealthcare clinical_information_center_mp100r_firmware 4.0

gehealthcare clinical_information_center_mp100r_firmware 5.0

gehealthcare carescape_telemetry_server_mp100r_firmware