SB2020012406 - Multiple vulnerabilities in GE CARESCAPE, ApexPro and Clinical Information Center systems



SB2020012406 - Multiple vulnerabilities in GE CARESCAPE, ApexPro and Clinical Information Center systems

Published: January 24, 2020

Security Bulletin ID SB2020012406
Severity
High
Patch available
NO
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 83% Medium 17%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2020-6962)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the web-based system configuration utility. A remote attacker can obtain arbitrary code execution.

Note: This vulnerability affects the following versions of GE products:

  • Clinical Information Center (CIC), Versions 4.X and 5.X
  • CARESCAPE Central Station (CSCS), Versions 2.X
  • B450, Version 2.X
  • B650, Version 1.X
  • B650, Version 2.X
  • B850, Version 1.X
  • B850, Version 2.X

2) Unprotected storage of credentials (CVE-ID: CVE-2020-6961)

The vulnerability allows a remote attacker to gain access to other users' credentials.

The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A remote attacker can obtain access to the SSH private key in configuration files.

Note: This vulnerability affects the following versions of CIC and CSCS:

  • Clinical Information Center (CIC), Versions 4.X and 5.X
  • CARESCAPE Central Station (CSCS), Versions 2.X

3) Use of hard-coded credentials (CVE-ID: CVE-2020-6963)

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to the affected products utilized hard coded SMB credentials. A remote unauthenticated attacker can access the affected system using the hard-coded credentials and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Note: This vulnerability affects the following versions of CIC and CSCS:

  • Clinical Information Center (CIC), Versions 4.X and 5.X
  • CARESCAPE Central Station (CSCS), Versions 1.X

4) Missing Authentication for Critical Function (CVE-ID: CVE-2020-6964)

The vulnerability allows a remote attacker to bypass authentication on an affected device.

 The vulnerability exists due to an issue in the integrated service for keyboard switching of the affected devices. A remote attacker can obtain remote keyboard input access without authentication over the network.

Note: This vulnerability affects the following versions of GE products:

  • Clinical Information Center (CIC), Versions 4.X and 5.X
  • CARESCAPE Central Station (CSCS), Versions 2.X

5) Arbitrary file upload (CVE-ID: CVE-2020-6965)

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file uploads in the software update mechanism. A remote authenticated attacker can upload arbitrary files on the system through a crafted update package.

Note: This vulnerability affects the following versions of GE products:

  • Clinical Information Center (CIC), Versions 4.X and 5.X
  • CARESCAPE Central Station (CSCS), Versions 1.X
  • B450, Version 2.X
  • B650, Version 1.X
  • B650, Version 2.X
  • B850, Version 1.X
  • B850, Version 2.X

6) Inadequate Encryption Strength (CVE-ID: CVE-2020-6966)

The vulnerability allows a remote attacker to execute arbitrary code on the target device.

The vulnerability exists due to the affected products utilize a weak encryption scheme for remote desktop control. A remote attacker can execute arbitrary code on devices on the network.

Note: This vulnerability affects the following versions of CIC and CSCS:

  • Clinical Information Center (CIC), Versions 4.X and 5.X
  • CARESCAPE Central Station (CSCS), Versions 1.X

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.