First published: Fri Jan 24 2020(Updated: )
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Gehealthcare Apexpro Telemetry Server Firmware | <=4.2 | |
Gehealthcare Apexpro Telemetry Server | ||
Gehealthcare Carescape Central Station Mai700 Firmware | =1.0 | |
Gehealthcare Carescape Central Station Mai700 | ||
Gehealthcare Carescape Central Station Mas700 Firmware | =1.0 | |
Gehealthcare Carescape Central Station Mas700 | ||
Gehealthcare Clinical Information Center Mp100d Firmware | =4.0 | |
Gehealthcare Clinical Information Center Mp100d Firmware | =5.0 | |
Gehealthcare Clinical Information Center Mp100d | ||
Gehealthcare Clinical Information Center Mp100r Firmware | =4.0 | |
Gehealthcare Clinical Information Center Mp100r Firmware | =5.0 | |
Gehealthcare Clinical Information Center Mp100r | ||
Gehealthcare Carescape Telemetry Server Mp100r Firmware | <=4.2 | |
Gehealthcare Carescape Telemetry Server Mp100r Firmware | =4.3 | |
Gehealthcare Carescape Telemetry Server Mp100r |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-6961 is critical (10 out of 10).
ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X.
Update to a version higher than 4.2 for ApexPro Telemetry Server, CARESCAPE Telemetry Server, and Clinical Information Center, and update to a version higher than 1.0 for CARESCAPE Central Station.
You can find more information about CVE-2020-6961 at the following references: [US-CERT Advisory](https://www.us-cert.gov/ics/advisories/icsma-20-023-01), [GE Healthcare Gateway Project Implementation Guide](https://www3.gehealthcare.com/~/media/downloads/us/support/site-planning/site-readiness/gehc-gateway_project_implementation_guide_pdf.pdf).
The Common Weakness Enumerations (CWE) associated with CVE-2020-6961 are CWE-522 and CWE-256.