PT-2018-9992 · Philips · Intellivue Patient Monitors Mx+3

Publicado

2018-06-05

·

Atualizado

2021-05-10

·

CVE-2018-10601

CVSS v2.0

5.4

Média

VetorAV:A/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: IntelliVue Patient Monitors MP Series versions Rev B-M IntelliVue Patient Monitors MX versions Rev J-M Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0, J.3 IntelliVue Patient Monitors X3/MX100 version Rev M
Description: The issue exposes an "echo" service, where an attacker can send a buffer to a chosen device address within the same subnet, which is then copied to the stack without boundary checks, resulting in a stack overflow.
Recommendations: For IntelliVue Patient Monitors MP Series versions Rev B-M, update the software to a version that fixes the vulnerability. For IntelliVue Patient Monitors MX versions Rev J-M, update the software to a version that fixes the vulnerability. For Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0, J.3, update the software to a version that fixes the vulnerability. For IntelliVue Patient Monitors X3/MX100 version Rev M, update the software to a version that fixes the vulnerability. As a temporary workaround, consider disabling the "echo" service until a patch is available.

Correção

Memory Corruption

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10601

Produtos afetados

Avalon Fetal/Maternal Monitors
Intellivue Patient Monitors Mp Series
Intellivue Patient Monitors Mx
Intellivue Patient Monitors X3/Mx100