CVE-2020-6963: Input Validation
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For ApexPro Telemetry Server (v4.2 and prior), CARESCAPE Telemetry Server (v4.2 and prior), Clinical Information Center (CIC) (v4.X and 5.X), and CARESCAPE Central Station (CSCS) (v1.X), mitigate the risk of hard-coded SMB credentials by preventing/limiting SMB network access to only the required systems (e.g., restrict SMB traffic with network firewall/ACL rules).
- Operational
For ApexPro Telemetry Server (v4.2 and prior), CARESCAPE Telemetry Server (v4.2 and prior), Clinical Information Center (CIC) (v4.X and 5.X), and CARESCAPE Central Station (CSCS) (v1.X), rotate or change any SMB credentials used by these systems since hard-coded SMB credentials may have been exposed.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-6963.
What is the severity of CVE-2020-6963?
The severity of CVE-2020-6963 is critical.
Which products are affected by CVE-2020-6963?
ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, and CARESCAPE Central Station (CSCS) Versions 1.X are affected by CVE-2020-6963.
What is the impact of CVE-2020-6963?
CVE-2020-6963 may allow an attacker to remotely execute commands.
Are there any fixes or patches available for CVE-2020-6963?
It is recommended to refer to the vendor's advisories and implementation guide for instructions on addressing CVE-2020-6963.