Input validation error in GE products - CVE-2020-6962
Published: January 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the web-based system configuration utility. A remote attacker can obtain arbitrary code execution.
Note: This vulnerability affects the following versions of GE products:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 2.X
- B450, Version 2.X
- B650, Version 1.X
- B650, Version 2.X
- B850, Version 1.X
- B850, Version 2.X
Affected software
CARESCAPE Telemetry Server
Clinical Information Center (CIC)
CARESCAPE Monitor B450
CARESCAPE Monitor B650
CARESCAPE Monitor B850
CARESCAPE Central Station (CSCS)