ICSMA-20-049-01
·
Published 2020-02-18
·
View on CISA ICS-CERT ↗
Spacelabs Xhibit Telemetry Receiver (XTR)
CVSS 9.8
CRITICAL
CISA KEV — Known Exploited
Risk Summary
A remote code execution vulnerability called BlueKeep (CVE-2019-0708) exists within the Remote Desktop Protocol (RDP) used by the Microsoft Windows operating systems listed below. An attacker can exploit this vulnerability to perform remote code execution on an unprotected system.
CVEs (1)
Remediations
- Spacelabs has determined the recommended remediation is to update to the newest release v1.2.1 or later. All deployed XTR hardware appliances are capable of update and should be updated. Many Spacelabs products are appliances and users are not intended to perform updates on them. Products or systems that are obsolete or are not able to be patched may use this alternate mitigation step to help protect against BlueKeep:
- Spacelabs also encourages users and administrators to review the Microsoft Security Advisory and the Microsoft Customer Guidance for CVE-2019-0708 and apply the appropriate mitigation measures as soon as possible.
- If you own an XTR device or have any questions about this security advisory, please contact Spacelabs at 1-800-522-7025 and select 2 for technical support. XTR is an appliance that has no user interface, so your service representative can help you to determine the installed version of software on your XTR product and will work to coordinate updates as needed.
- For additional information about this vulnerability, please see the Spacelabs Security Advisory.
Affected Vendors
Spacelabs
Affected Products (10)
Spacelabs
·
Windows Server 2003
vers:all/*
Spacelabs
·
Windows XP
vers:all/*
Spacelabs
·
Windows Server 2008
vers:all/*
Spacelabs
·
Xhibit Telemetry Receiver (XTR) Model number 96280
1.0.2
Spacelabs
·
Windows 2000
vers:all/*
Spacelabs
·
Windows 7
vers:all/*
Spacelabs
·
Windows Vista
vers:all/*
Spacelabs
·
Windows Server 2003 R2
vers:all/*
Spacelabs
·
Windows Server 2008 R2
vers:all/*
Spacelabs
·
Arkon (99999)
vers:all/*
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more