Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2020-6966

Disclosure Date: January 24, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
10.0 Critical
Impact Score:
6
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Changed
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • gehealthcare

Products

  • apexpro telemetry server firmware,
  • carescape central station mai700 firmware 1.0,
  • carescape central station mas700 firmware 1.0,
  • carescape telemetry server mp100r firmware,
  • clinical information center mp100d firmware 4.0,
  • clinical information center mp100d firmware 5.0,
  • clinical information center mp100r firmware 4.0,
  • clinical information center mp100r firmware 5.0

Additional Info

Technical Analysis