Multiple Vulnerabilities in GE Medical Devices

Multiple Vulnerabilities in GE Medical Devices

Component Affected
GE  ApexPro Telemetry  Server,  Versions  4.2 and  prior
• GE CARESCAPE Telemetry Server, Version 4.3 and prior
• GE Clinical  Information  Center (CIC),  Versions 4.X and 5.X
• GE CARESCAPE  Central Station  (CSCS), Versions 1.X  and 2.X
• GE CARESCAPE  B450Monitor, Version 2.X
• GE CARESCAPE  B650 Monitor, Version 1.X and 2.X
• GE CARESCAPE  B850Monitor, Version 1.X, and  2.X

Overview

Multiple  vulnerabilities have  been reported in  GE  Medical  Devices,  which could be exploited by  an unauthenticated  remote
attacker to obtain potentially sensitive information,  execute arbitrary code,  and escalate privileges on a targeted system.

Description

1. Information Disclosure Vulnerability (  CVE-2020-6961 )

This vulnerability exists in  GE  Products due to the unprotected storage of  SSH private keys.  A remote attacker could exploit this
vulnerability to obtain the SSH private key from configuration files which could be used to conduct further attacks on the targeted
system. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information,  which could lead to
further attacks.

2. Remote Code Execution Vulnerability ( CVE-2020-6962 )

This vulnerability exists in  GE  Products due to improper validation of user input.  A remote attacker could exploit this vulnerability
by sending especially -crafted data to the web-based  system configuration utility. Successful exploitation of this vulnerability could
allow an attacker to execute arbitrary code on the targeted system.

3. Remote Code Execution Vulnerability ( CVE-2020-6963 )
This vulnerability exists in  GE  Products due to the use of hard-coded SMB  credentials. A remote attacker could exploit this
vulnerability to execute arbitrary code on the targeted system.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the targeted system.

4. Elevation of Privilege Vulnerability  ( CVE-2020-6964 )
This vulnerability exists in  GE  Products due to missing authentication in the integrated service for keyboard switching. A remote
attacker could exploit this vulnerability to escalate privileges and take control of the keyboard input device. Successful
exploitation of this vulnerability could allow the attacker to gain elevated privileges of the targeted system.

5. Unrestricted File Upload Vulnerability  ( CVE-2020-6965 )
This vulnerability exists in  GE  Products due to improper software update mechanism. A remote attacker could exploit this
vulnerability by sending a crafted update package to upload arbitrary files on the targeted system.  Successful exploitation of this
vulnerability could allow the attacker to upload arbitrary files on the system through a crafted update package.

Comments

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Some Dark web Links

Cyber Security Audits