← Back to home
ICSMA-20-023-01  ·  Published 2020-01-23  ·  View on CISA ICS-CERT ↗

GE CARESCAPE, ApexPro, and Clinical Information Center systems

CVSS 10.0 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could occur when an attacker gains access to the mission critical (MC) and/or information exchange (IX) networks due to improper configuration or physical access to devices. An exploit could result in a loss of monitoring and/or loss of alarms during active patient monitoring. These vulnerabilities, if exploited, may allow an attacker to obtain PHI data, make changes at the operating system level of the device, with effects such as rendering the device unusable, otherwise interfering with the function of the device and/or making certain changes to alarm settings on connected patient monitors, and/or utilizing services used for remote viewing and control of devices on the network to access the clinical user interface and make changes to device settings and alarm limits, which could result in missed or unnecessary alarms or silencing of some alarms.

Remediations

  • GE recommends users confirm the proper configuration of the MC and IX networks to ensure that the isolation and configuration meet the requirements listed in the Patient Monitoring Network Configuration Guide, CARESCAPE Network Configuration Guide, and product technical and service manuals. These can be obtained by contacting GE via the customer support portal with a valid support account. A properly isolated network requires an attacker to gain physical access in order to carry out an exploit.
  • GE recommends that, in addition to applying network management best practices, users ensure:

Affected Vendors

General Electric (GE)

Affected Products (11)

General Electric (GE) · B450 2.X
General Electric (GE) · B850 2.X
General Electric (GE) · B650 1.X
General Electric (GE) · CARESCAPE Central Station (CSCS) 2.X
General Electric (GE) · ApexPro Telemetry Server <= 4.2
General Electric (GE) · CARESCAPE Telemetry Server 4.3
General Electric (GE) · CARESCAPE Central Station (CSCS) 1.X
General Electric (GE) · B850 1.X
General Electric (GE) · CARESCAPE Telemetry Server <= 4.2
General Electric (GE) · B650 2.X
General Electric (GE) · Clinical Information Center (CIC) 4.X | 5.X

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more