CVE-2020-16216: Philips Patient Monitoring Devices Improper Input Validation
In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly, which can induce a denial-of-service condition through a system restart.
Other sources
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior. The product receives input or data but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly, which can induce a denial-of-service condition through a system restart.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16216?
The severity of CVE-2020-16216 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2020-16216?
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior are affected by CVE-2020-16216.
What is the vulnerability description of CVE-2020-16216?
CVE-2020-16216 is a vulnerability in the Patient Information Center iX (PICiX) software, PerformanceBridge Focal Point software, and IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90, as well as IntelliVue X3 and X2, that allows the product to receive input or data without proper validation or incorporation.
How can I fix CVE-2020-16216?
To fix CVE-2020-16216, it is recommended to apply the necessary security patches or updates provided by Philips, the vendor of the affected software and devices.
Where can I find more information about CVE-2020-16216?
You can find more information about CVE-2020-16216 on the US-CERT website at https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01.