Input validation error in GE products - CVE-2020-6962
Published: January 24, 2020
ApexPro Telemetry Server
CARESCAPE Telemetry Server
Clinical Information Center (CIC)
CARESCAPE Monitor B450
CARESCAPE Monitor B650
CARESCAPE Monitor B850
CARESCAPE Central Station (CSCS)
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the web-based system configuration utility. A remote attacker can obtain arbitrary code execution.
Note: This vulnerability affects the following versions of GE products:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 2.X
- B450, Version 2.X
- B650, Version 1.X
- B650, Version 2.X
- B850, Version 1.X
- B850, Version 2.X