PT-2018-8519 · Philips · Philips Intellivue Mx40
Published
2018-04-30
·
Updated
2019-10-09
·
CVE-2017-9658
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Philips IntelliVue MX40 Version B.06.18 and earlier
Description
The issue arises when certain 802.11 network management messages unnecessarily trigger wireless access point blacklisting security defenses. This can require hospital staff to intervene, resetting the device to reestablish a network connection. During this time, the device can either connect to an alternative access point or remain in local monitoring mode until reset. The estimated number of potentially affected devices is not specified.
Recommendations
For Philips IntelliVue MX40 Version B.06.18 and earlier, apply the software update to Version B.06.18 or later to fix the issue and implement mitigations that reduce the risk associated with improper handling of exceptional conditions.
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Philips Intellivue Mx40