Inadequate Encryption Strength in GE products - CVE-2020-6966
Published: January 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target device.
The vulnerability exists due to the affected products utilize a weak encryption scheme for remote desktop control. A remote attacker can execute arbitrary code on devices on the network.
Note: This vulnerability affects the following versions of CIC and CSCS:
- Clinical Information Center (CIC), Versions 4.X and 5.X
- CARESCAPE Central Station (CSCS), Versions 1.X
Affected software
CARESCAPE Telemetry Server
Clinical Information Center (CIC)
CARESCAPE Central Station (CSCS)