Spacelabs Xhibit Telemetry Receiver (XTR) 96280 v1.0.2 — unpatched Windows RDP flaw (BlueKeep)
Why this is on the list
Vendor-confirmed: affected range, remediation and fixed version come from the vendor or CNA advisory. Exploitation evidence is component scoped: CISA lists the underlying component vulnerability as known-exploited; that is not evidence of exploitation observed against this product.
- CISA added this to its Known Exploited Vulnerabilities Catalog on 2021-11-03.
- CISA records it as having been used in ransomware campaigns.
Patient telemetry receiver on the clinical network. It relays continuous vital-sign monitoring; loss or disruption affects patient monitoring, and the appliance sits on the same network segment as other clinical systems.
Does this apply to your version?
An affected range is on record, derived from CISA's exploitation evidence rather than published by the product's vendor. Check your own release against it, or enter it in the lookup and Patient Protect will evaluate it for you.
Affected: =1.0.2 · Fixed in 1.2.1
Check your versionWhat to do
Update the Xhibit Telemetry Receiver (XTR) to version 1.2.1 or later. Spacelabs states all deployed XTR hardware appliances are capable of update and should be updated; XTR is a serviced appliance with no user interface, so arrange the update through Spacelabs technical support.
- Vendor
- Spacelabs
- Product
- Xhibit Telemetry Receiver (XTR) Model number 96280
- Affected versions
- =1.0.2
- Fixed in
- 1.2.1
- First published
- 2026-09-08
Where this comes from
4 sources- CISA
Source assertion: affected_range:cisa
Read the CISA record - CISAPrimary government source
Confirms active exploitation · Informs severity
Vulnerability is exploited in the wild (CISA KEV listing)
Read the CISA record - CISA
Source assertion: vendor_fix
Read the CISA record - FIRSTSupporting intelligence
Informs severity
EPSS estimates a >99% probability that this vulnerability will be exploited in the next 30 days. It is a forecast about the vulnerability, not a statement about whether your installation is affected.
About EPSS
How this was assessed
- CISA medical advisory ICSMA-20-049-01 records Xhibit Telemetry Receiver Model 96280 v1.0.2 as affected by CVE-2019-0708, a Microsoft Windows Remote Desktop flaw in the appliance's underlying operating system. CISA lists CVE-2019-0708 in its Known Exploited Vulnerabilities catalog
- that listing covers the underlying Microsoft Windows Remote Desktop vulnerability and is not evidence of exploitation observed against the Spacelabs appliance. Spacelabs' remediation is to update deployed XTR appliances to v1.2.1 or later.
Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.
Do you run this?
Check your own version against the ledger — it may or may not fall inside the affected range.
Check your technology