CVE-2020-16214: Philips Patient Monitoring Devices Improper Neutralization of Formula Elements in a CSV File
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.
Other sources
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior. The software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-16214.
What is the severity of CVE-2020-16214?
The severity of CVE-2020-16214 is medium.
Which software versions are affected by CVE-2020-16214?
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior.
How can I fix CVE-2020-16214?
Apply the necessary patches or updates provided by Philips.
Where can I find more information about CVE-2020-16214?
You can find more information about CVE-2020-16214 at the following reference: [https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01]