First published: Tue Jun 05 2018(Updated: )
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Intellivue Mp2 Firmware | ||
Philips Intellivue Mp2 | ||
Philips Intellivue X2 Firmware | ||
Philips Intellivue X2 | ||
Philips Intellivue Mp30 Firmware | ||
Philips Intellivue Mp30 | ||
Philips Intellivue Mp50 Firmware | ||
Philips Intellivue Mp50 | ||
Philips Intellivue Mp70 Firmware | ||
Philips Intellivue Mp70 | ||
Philips Intellivue Np90 Firmware | ||
Philips Intellivue Np90 | ||
Philips Intellivue Mx700 Firmware | ||
Philips Intellivue Mx700 | ||
Philips Intellivue Mx800 Firmware | ||
Philips Intellivue Mx800 | ||
Philips Intellivue Mx400 Firmware | ||
Philips Intellivue Mx400 | ||
Philips Intellivue Mx450 Firmware | ||
Philips Intellivue Mx450 | ||
Philips Intellivue Mx500 Firmware | ||
Philips Intellivue Mx500 | ||
Philips Intellivue Mx550 Firmware | ||
Philips Intellivue Mx550 | ||
Philips Intellivue X3 Firmware | ||
Philips Intellivue X3 | ||
Philips Intellivue Mx100 Firmware | ||
Philips Intellivue Mx100 | ||
Philips Avalon Fetal\/maternal Monitors Fm20 Firmware | ||
Philips Avalon Fetal\/maternal Monitors Fm20 | ||
Philips Avalon Fetal\/maternal Monitors Fm30 Firmware | ||
Philips Avalon Fetal\/maternal Monitors Fm30 | ||
Philips Avalon Fetal\/maternal Monitors Fm40 Firmware | ||
Philips Avalon Fetal\/maternal Monitors Fm40 | ||
Philips Avalon Fetal\/maternal Monitors Fm50 Firmware | ||
Philips Avalon Fetal\/maternal Monitors Fm50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10601 is high with a severity value of 8.2.
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 are affected by CVE-2018-10601.
CVE-2018-10601 is a vulnerability in IntelliVue Patient Monitors and Avalon Fetal/Maternal Monitors that could allow an attacker to remotely execute arbitrary code.
To fix CVE-2018-10601, it is recommended to apply the necessary software updates provided by Philips.
You can find more information about CVE-2018-10601 in the advisory published by the US-CERT.