CVE-2020-6966

CRITICAL

GE Healthcare ApexPro Telemetry Server < 4.2 - Inadequate Encryption Strength

Title source: llm
STIX 2.1

Description

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.

Scores

CVSS v3 10.0
EPSS 0.0222
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-326
Status published
Products (8)
gehealthcare/apexpro_telemetry_server_firmware < 4.2
gehealthcare/carescape_central_station_mai700_firmware 1.0
gehealthcare/carescape_central_station_mas700_firmware 1.0
gehealthcare/carescape_telemetry_server_mp100r_firmware < 4.2
gehealthcare/clinical_information_center_mp100d_firmware 4.0
gehealthcare/clinical_information_center_mp100d_firmware 5.0
gehealthcare/clinical_information_center_mp100r_firmware 4.0
gehealthcare/clinical_information_center_mp100r_firmware 5.0
Published Jan 24, 2020
Tracked Since Feb 18, 2026