Arbitrary file upload in GE products - CVE-2020-6965
Published: January 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file uploads in the software update mechanism. A remote authenticated attacker can upload arbitrary files on the system through a crafted update package.
Note: This vulnerability affects the following versions of GE products:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 1.X
- B450, Version 2.X
- B650, Version 1.X
- B650, Version 2.X
- B850, Version 1.X
- B850, Version 2.X
Affected software
CARESCAPE Telemetry Server
Clinical Information Center (CIC)
CARESCAPE Monitor B450
CARESCAPE Monitor B650
CARESCAPE Monitor B850
CARESCAPE Central Station (CSCS)