CVE-2020-6965: Input Validation
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software update mechanism allows an authenticated attacker to upload arbitrary files on the system through a crafted update package.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6965?
CVE-2020-6965 is a vulnerability in ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, and B850 Version 2.X.
How severe is CVE-2020-6965?
CVE-2020-6965 has a severity rating of 9.9 (Critical).
How does CVE-2020-6965 affect Gehealthcare Apexpro Telemetry Server Firmware?
CVE-2020-6965 affects Gehealthcare Apexpro Telemetry Server Firmware versions up to 4.2
How can the Gehealthcare Carescape B450 Monitor Firmware be vulnerable to CVE-2020-6965?
The Gehealthcare Carescape B450 Monitor Firmware version 2.0 is vulnerable to CVE-2020-6965.
Where can I find more information about CVE-2020-6965?
You can find more information about CVE-2020-6965 at the following references: [US-CERT Advisory](https://www.us-cert.gov/ics/advisories/icsma-20-023-01) and [GE Healthcare Gateway Project Implementation Guide](https://www3.gehealthcare.com/~/media/downloads/us/support/site-planning/site-readiness/gehc-gateway_project_implementation_guide_pdf.pdf).