Skip to main content

GE Healthcare ApexPro, CARESCAPE, and CIC Vulnerabilities

GE Healthcare has released details of multiple vulnerabilities affecting their ApexPro, CARESCAPE, and Clinical Information Center (CIC) patient monitoring products. They claim an unauthenticated user on the same network could take control of an affected device, obtain SSH private keys, or alter diagnostic and monitoring data.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

GE Healthcare has released details of multiple vulnerabilities affecting their ApexPro, CARESCAPE, and Clinical Information Center (CIC) patient monitoring products. They claim an unauthenticated user on the same network could take control of an affected device, obtain SSH private keys, or alter diagnostic and monitoring data.


Affected platforms

The following platforms are known to be affected:

  • GE Healthcare Monitoring platforms:
    • ApexPro Telemetry Server - Versions 4.2 and earlier
    • CARESCAPE Telemetry Server - Versions 4.2 and earlier
    • Clinical Information Center (CIC) - Versions 4.X and 5.X
    • CARESCAPE Central Station (CSCS) - Versions 2.X and 1.X
    • B450 - Version 1.X
    • B650 - Versions 1.X and 2.X
    • B850 - Versions 1.X and 2.X


Remediation steps

Type Step

At the time of publication, GE Healthcare are recommending users confirm their MC and IX networks are properly configured in accordance with technical guides for their products. Affected organisations are encouraged to contact GE Healthcare via their support portal to obtain these technical guides.

GE Healthcare has also suggested the following mitigation steps be applied:

  • Block all incoming traffic to the MC and IX networks from the following ports:
    • TCP - 22, 5225, 5800, 5900, 10000, and 10001
    • TCP/UDP - 137, 138, 129, and 445
  • Restrict physical access to affected Central Stations, Telemetry Servers, and the MC and IC networks
  • Change default Webmin passwords

Last edited: 29 June 2021 12:00 pm