CVE-2018-10601: High severity Philips Intellivue Mp2 Firmware vulnerability
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10601?
The severity of CVE-2018-10601 is high with a severity value of 8.2.
Which software versions are affected by CVE-2018-10601?
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 are affected by CVE-2018-10601.
What is the vulnerability description of CVE-2018-10601?
CVE-2018-10601 is a vulnerability in IntelliVue Patient Monitors and Avalon Fetal/Maternal Monitors that could allow an attacker to remotely execute arbitrary code.
How can I fix CVE-2018-10601?
To fix CVE-2018-10601, it is recommended to apply the necessary software updates provided by Philips.
Where can I find more information about CVE-2018-10601?
You can find more information about CVE-2018-10601 in the advisory published by the US-CERT.