Apexpro Telemetry Server FirmwareOperating system · Gehealthcare

CVE-2020-6963

CRITICAL · 10.0 CVSS v3.1 Published 2020-01-24
Fix available
A fix is available. Upgrade to after 4.2 or later.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · moderate confidence

Multiple GE Healthcare telemetry and clinical monitoring products (ApexPro Telemetry Server, CARESCAPE Telemetry Server, Clinical Information Center, CARESCAPE Central Station) contain hard-coded SMB credentials embedded in the firmware/software. An attacker with network access to these systems can use the known credentials to authenticate via SMB and execute arbitrary code remotely.

MitigationReplace default hard-coded credentials with unique, strong credentials; implement network segmentation to restrict access to telemetry servers; apply vendor patches when available; monitor for unauthorized SMB authentication attempts.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Apexpro Telemetry Server FirmwareOperating system
Affected:<= 4.2
Carescape Central Station Mai700 FirmwareOperating system
Affected:= 1.0
Carescape Central Station Mas700 FirmwareOperating system
Affected:= 1.0
Clinical Information Center Mp100d FirmwareOperating system
Affected:= 4.0= 5.0
Clinical Information Center Mp100r FirmwareOperating system
Affected:= 4.0= 5.0
Carescape Telemetry Server Mp100r FirmwareOperating system
Affected:<= 4.2

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify the installed GE Healthcare product model
    Locate the product label, system information screen, or documentation that shows the exact model name (ApexPro Telemetry Server, CARESCAPE Central Station Mai700/Mas700, Clinical Information Center Mp100d/Mp100r, or CARESCAPE Telemetry Server Mp100r)
    Affected if The product model matches one of the affected models listed in the CVE
  2. Determine the firmware version
    Access the device system settings, about menu, or use the vendor-provided administrative interface to retrieve the current firmware version
    Affected if The firmware version falls within the affected ranges: ApexPro Telemetry Server <= 4.2, CARESCAPE Central Station = 1.0, Clinical Information Center = 4.0 or 5.0, CARESCAPE Telemetry Server Mp100r <= 4.2
  3. Verify SMB service accessibility
    Check if port 445 (SMB) is open and reachable on the device from the network using tools like netstat, nmap, or the device's own portscan feature if available
    Affected if SMB ports are exposed and accessible from network segments outside the local management network
  4. Inspect network configuration for SMB exposure
    Review the device network settings, firewall rules, or VLAN configuration to determine if SMB is enabled and accessible from non-local subnets
    Affected if SMB is enabled and the device is reachable from network segments beyond the local clinical network
  5. Audit SMB authentication logs for anomalous activity
    Review system or security logs for SMB authentication events, particularly from unexpected source IP addresses or failed authentication attempts
    Affected if SMB authentication logs show connections from unknown external sources or evidence of brute-force attempts

A user is affected if their system is a listed GE Healthcare product model running the specified firmware version with SMB accessible from the network.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to a release after 4.2
Interim mitigation

Replace default hard-coded credentials with unique, strong credentials; implement network segmentation to restrict access to telemetry servers; apply vendor patches when available; monitor for unauthorized SMB authentication attempts.

Recommended fix Moderate confidence

Firmware version > 4.2 for Apexpro Telemetry Server and Carescape Telemetry Server; firmware version > 1.0 for Carescape Central Station (Mai700 and Mas700); firmware version > 5.0 for Clinical Information Center (Mp100d and Mp100r) - contact GE Healthcare for exact fixed versions

  1. 1. Contact GE Healthcare technical support to obtain the latest firmware version that addresses CVE-2020-6963
  2. 2. Schedule a maintenance window for the medical device firmware update
  3. 3. Ensure the update is performed by authorized GE Healthcare service personnel or according to vendor-provided firmware update procedures
  4. 4. After updating, change any default credentials as recommended by GE Healthcare
  5. 5. Verify the firmware version has been successfully updated and the hard-coded credentials vulnerability is remediated
  6. 6. Review and monitor the device for any suspicious activity
Caveat Medical device firmware updates may require vendor support, testing, and validation; ensure updates do not impact device regulatory certifications or patient safety functions

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Apexpro Telemetry Server Firmware Scoped from the published advisory
  • Consultation12.0 h
  • Implementation24.0 h
  • Testing16.0 h
  • Review / QA8.0 h
60.0 hours of engineering $10,560
Get the upgrade done

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $16,896.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2020-6963 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2020-6963 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data