SB2020012406 - Multiple vulnerabilities in GE CARESCAPE, ApexPro and Clinical Information Center systems
Published: January 24, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2020-6962)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the web-based system configuration utility. A remote attacker can obtain arbitrary code execution.
Note: This vulnerability affects the following versions of GE products:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 2.X
- B450, Version 2.X
- B650, Version 1.X
- B650, Version 2.X
- B850, Version 1.X
- B850, Version 2.X
2) Unprotected storage of credentials (CVE-ID: CVE-2020-6961)
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A remote attacker can obtain access to the SSH private key in configuration files.
Note: This vulnerability affects the following versions of CIC and CSCS:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 2.X
3) Use of hard-coded credentials (CVE-ID: CVE-2020-6963)
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to the affected products utilized hard coded SMB credentials. A remote unauthenticated attacker can access the affected system using the hard-coded credentials and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note: This vulnerability affects the following versions of CIC and CSCS:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 1.X
4) Missing Authentication for Critical Function (CVE-ID: CVE-2020-6964)
The vulnerability allows a remote attacker to bypass authentication on an affected device.
The vulnerability exists due to an issue in the integrated service for keyboard switching of the affected devices. A remote attacker can obtain remote keyboard input access without authentication over the network.
Note: This vulnerability affects the following versions of GE products:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 2.X
5) Arbitrary file upload (CVE-ID: CVE-2020-6965)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file uploads in the software update mechanism. A remote authenticated attacker can upload arbitrary files on the system through a crafted update package.
Note: This vulnerability affects the following versions of GE products:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 1.X
- B450, Version 2.X
- B650, Version 1.X
- B650, Version 2.X
- B850, Version 1.X
- B850, Version 2.X
6) Inadequate Encryption Strength (CVE-ID: CVE-2020-6966)
The vulnerability allows a remote attacker to execute arbitrary code on the target device.
The vulnerability exists due to the affected products utilize a weak encryption scheme for remote desktop control. A remote attacker can execute arbitrary code on devices on the network.
Note: This vulnerability affects the following versions of CIC and CSCS:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 1.X
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.