CVE-2020-6964: High severity Gehealthcare Apexpro Telemetry Server Firmware vulnerability
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6964?
CVE-2020-6964 is a vulnerability that exists in ApexPro Telemetry Server Versions 4.2 and prior.
Which software versions are affected by CVE-2020-6964?
ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X are affected.
What is the severity of CVE-2020-6964?
The severity of CVE-2020-6964 is high, with a severity score of 8.6.
Where can I find more information about CVE-2020-6964?
You can find more information about CVE-2020-6964 at the following references: [US-CERT Advisory](https://www.us-cert.gov/ics/advisories/icsma-20-023-01), [GE Healthcare Gateway Project Implementation Guide](https://www3.gehealthcare.com/~/media/downloads/us/support/site-planning/site-readiness/gehc-gateway_project_implementation_guide_pdf.pdf).
Is there a fix available for CVE-2020-6964?
Please refer to the vendor's security advisory or contact GE Healthcare for information on available fixes for CVE-2020-6964.