PT-2018-9988 · Philips · Intellivue Patient Monitors Mx+3

Published

2018-06-05

·

Updated

2021-05-10

·

CVE-2018-10597

CVSS v2.0

5.4

Medium

VectorAV:A/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: IntelliVue Patient Monitors MP Series versions Rev B-M IntelliVue Patient Monitors MX versions Rev J-M Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0, J.3 IntelliVue Patient Monitors X3/MX100 version Rev M
Description: The issue allows an unauthenticated attacker to access memory from an attacker-chosen device address within the same subnet, utilizing a "write-what-where" technique.
Recommendations: For IntelliVue Patient Monitors MP Series versions Rev B-M, restrict access to the device within the subnet to minimize the risk of exploitation. For IntelliVue Patient Monitors MX versions Rev J-M, consider implementing network segmentation to limit the attack surface. For Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0, J.3, limit device access to trusted networks only. For IntelliVue Patient Monitors X3/MX100 version Rev M, apply strict access controls to prevent unauthorized device access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10597

Affected Products

Avalon Fetal/Maternal Monitors
Intellivue Patient Monitors Mp Series
Intellivue Patient Monitors Mx
Intellivue Patient Monitors X3/Mx100