CVE-2020-6966: Gehealthcare Apexpro Telemetry Server Firmware
Critical severity, CVSS 10.0. EPSS: 2.2% chance of exploitation in the next 30 days.
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.
Affected products
- Gehealthcare Apexpro Telemetry Server Firmware: up to and including 4.2
- Gehealthcare Carescape Central Station MAI700 Firmware: version 1.0 only
- Gehealthcare Carescape Central Station MAS700 Firmware: version 1.0 only
- Gehealthcare Carescape Telemetry Server MP100R Firmware: up to and including 4.2
- Gehealthcare Clinical Information Center MP100D Firmware: version 4.0 only; version 5.0 only
- Gehealthcare Clinical Information Center MP100R Firmware: version 4.0 only; version 5.0 only
Published 2020-01-24. Last modified 2026-06-17.