Product:

Carescape_central_station_mas700_firmware

(Gehealthcare)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 6
Date Id Summary Products Score Patch Annotated
2020-01-24 CVE-2020-6964 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network. Apexpro_telemetry_server_firmware, Carescape_central_station_mai700_firmware, Carescape_central_station_mas700_firmware, Carescape_telemetry_server_mp100r_firmware, Clinical_information_center_mp100d_firmware, Clinical_information_center_mp100r_firmware 8.6
2020-01-24 CVE-2020-6962 In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an attacker to... Apexpro_telemetry_server_firmware, Carescape_b450_monitor_firmware, Carescape_b650_monitor_firmware, Carescape_b850_monitor_firmware, Carescape_central_station_mai700_firmware, Carescape_central_station_mas700_firmware, Carescape_telemetry_server_mp100r_firmware, Clinical_information_center_mp100d_firmware, Clinical_information_center_mp100r_firmware 10.0
2020-01-24 CVE-2020-6966 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network. Apexpro_telemetry_server_firmware, Carescape_central_station_mai700_firmware, Carescape_central_station_mas700_firmware, Carescape_telemetry_server_mp100r_firmware, Clinical_information_center_mp100d_firmware, Clinical_information_center_mp100r_firmware 10.0
2020-01-24 CVE-2020-6961 In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files. Apexpro_telemetry_server_firmware, Carescape_central_station_mai700_firmware, Carescape_central_station_mas700_firmware, Carescape_telemetry_server_mp100r_firmware, Clinical_information_center_mp100d_firmware, Clinical_information_center_mp100r_firmware 10.0
2020-01-24 CVE-2020-6965 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software update mechanism allows an authenticated attacker to upload arbitrary files on the system through a crafted update package. Apexpro_telemetry_server_firmware, Carescape_b450_monitor_firmware, Carescape_b650_monitor_firmware, Carescape_b850_monitor_firmware, Carescape_central_station_mai700_firmware, Carescape_central_station_mas700_firmware, Carescape_telemetry_server_mp100r_firmware, Clinical_information_center_mp100d_firmware, Clinical_information_center_mp100r_firmware 9.9
2020-01-24 CVE-2020-6963 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code. Apexpro_telemetry_server_firmware, Carescape_central_station_mai700_firmware, Carescape_central_station_mas700_firmware, Carescape_telemetry_server_mp100r_firmware, Clinical_information_center_mp100d_firmware, Clinical_information_center_mp100r_firmware 10.0