Multiple Vulnerabilities in GE Medical Devices
Multiple Vulnerabilities in GE Medical Devices
Component Affected
• GE ApexPro Telemetry Server, Versions 4.2 and prior
• GE CARESCAPE Telemetry Server, Version 4.3 and prior
• GE Clinical Information Center (CIC), Versions 4.X and 5.X
• GE CARESCAPE Central Station (CSCS), Versions 1.X and 2.X
• GE CARESCAPE B450Monitor, Version 2.X
• GE CARESCAPE B650 Monitor, Version 1.X and 2.X
• GE CARESCAPE B850Monitor, Version 1.X, and 2.X
Overview
Multiple vulnerabilities have been reported in GE Medical Devices, which could be exploited by an unauthenticated remote
attacker to obtain potentially sensitive information, execute arbitrary code, and escalate privileges on a targeted system.
Description
1. Information Disclosure Vulnerability ( CVE-2020-6961 )
This vulnerability exists in GE Products due to the unprotected storage of SSH private keys. A remote attacker could exploit this
vulnerability to obtain the SSH private key from configuration files which could be used to conduct further attacks on the targeted
system. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information, which could lead to
further attacks.
2. Remote Code Execution Vulnerability ( CVE-2020-6962 )
This vulnerability exists in GE Products due to improper validation of user input. A remote attacker could exploit this vulnerability
by sending especially -crafted data to the web-based system configuration utility. Successful exploitation of this vulnerability could
allow an attacker to execute arbitrary code on the targeted system.
3. Remote Code Execution Vulnerability ( CVE-2020-6963 )
This vulnerability exists in GE Products due to the use of hard-coded SMB credentials. A remote attacker could exploit this
vulnerability to execute arbitrary code on the targeted system.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the targeted system.
4. Elevation of Privilege Vulnerability ( CVE-2020-6964 )
This vulnerability exists in GE Products due to missing authentication in the integrated service for keyboard switching. A remote
attacker could exploit this vulnerability to escalate privileges and take control of the keyboard input device. Successful
exploitation of this vulnerability could allow the attacker to gain elevated privileges of the targeted system.
5. Unrestricted File Upload Vulnerability ( CVE-2020-6965 )
This vulnerability exists in GE Products due to improper software update mechanism. A remote attacker could exploit this
vulnerability by sending a crafted update package to upload arbitrary files on the targeted system. Successful exploitation of this
vulnerability could allow the attacker to upload arbitrary files on the system through a crafted update package.
Component Affected
• GE ApexPro Telemetry Server, Versions 4.2 and prior
• GE CARESCAPE Telemetry Server, Version 4.3 and prior
• GE Clinical Information Center (CIC), Versions 4.X and 5.X
• GE CARESCAPE Central Station (CSCS), Versions 1.X and 2.X
• GE CARESCAPE B450Monitor, Version 2.X
• GE CARESCAPE B650 Monitor, Version 1.X and 2.X
• GE CARESCAPE B850Monitor, Version 1.X, and 2.X
Overview
Multiple vulnerabilities have been reported in GE Medical Devices, which could be exploited by an unauthenticated remote
attacker to obtain potentially sensitive information, execute arbitrary code, and escalate privileges on a targeted system.
Description
1. Information Disclosure Vulnerability ( CVE-2020-6961 )
This vulnerability exists in GE Products due to the unprotected storage of SSH private keys. A remote attacker could exploit this
vulnerability to obtain the SSH private key from configuration files which could be used to conduct further attacks on the targeted
system. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information, which could lead to
further attacks.
2. Remote Code Execution Vulnerability ( CVE-2020-6962 )
This vulnerability exists in GE Products due to improper validation of user input. A remote attacker could exploit this vulnerability
by sending especially -crafted data to the web-based system configuration utility. Successful exploitation of this vulnerability could
allow an attacker to execute arbitrary code on the targeted system.
3. Remote Code Execution Vulnerability ( CVE-2020-6963 )
This vulnerability exists in GE Products due to the use of hard-coded SMB credentials. A remote attacker could exploit this
vulnerability to execute arbitrary code on the targeted system.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the targeted system.
4. Elevation of Privilege Vulnerability ( CVE-2020-6964 )
This vulnerability exists in GE Products due to missing authentication in the integrated service for keyboard switching. A remote
attacker could exploit this vulnerability to escalate privileges and take control of the keyboard input device. Successful
exploitation of this vulnerability could allow the attacker to gain elevated privileges of the targeted system.
5. Unrestricted File Upload Vulnerability ( CVE-2020-6965 )
This vulnerability exists in GE Products due to improper software update mechanism. A remote attacker could exploit this
vulnerability by sending a crafted update package to upload arbitrary files on the targeted system. Successful exploitation of this
vulnerability could allow the attacker to upload arbitrary files on the system through a crafted update package.
Comments
Post a Comment