CVE-2020-6966: Weak Encryption
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6966?
CVE-2020-6966 is a vulnerability in ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X that utilizes weak encryption for remote desktop control.
What is the severity of CVE-2020-6966?
CVE-2020-6966 has a severity rating of critical with a value of 10.
How does CVE-2020-6966 affect Gehealthcare Apexpro Telemetry Server Firmware?
CVE-2020-6966 affects Gehealthcare Apexpro Telemetry Server Firmware version 4.2 and prior.
How can I fix CVE-2020-6966?
To fix CVE-2020-6966, it is recommended to upgrade to a version of the affected products that addresses the weak encryption vulnerability.
Where can I find more information about CVE-2020-6966?
You can find more information about CVE-2020-6966 on the US-CERT website and the GE Healthcare website.