CVE-2020-6961
24.01.2020, 17:15
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.Enginsight
Vendor | Product | Version |
---|---|---|
gehealthcare | apexpro_telemetry_server_firmware | 𝑥 ≤ 4.2 |
gehealthcare | carescape_central_station_mai700_firmware | 1.0 |
gehealthcare | carescape_central_station_mas700_firmware | 1.0 |
gehealthcare | clinical_information_center_mp100d_firmware | 4.0 |
gehealthcare | clinical_information_center_mp100d_firmware | 5.0 |
gehealthcare | clinical_information_center_mp100r_firmware | 4.0 |
gehealthcare | clinical_information_center_mp100r_firmware | 5.0 |
gehealthcare | carescape_telemetry_server_mp100r_firmware | 𝑥 ≤ 4.2 |
gehealthcare | carescape_telemetry_server_mp100r_firmware | 4.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-256 - Plaintext Storage of a PasswordStoring a password in plaintext may result in a system compromise.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.