CVE-2020-16218: Philips Patient Monitoring Devices Cross-site Scripting
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful exploitation could lead to unauthorized access to patient data via a read-only web application.
Other sources
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful exploitation could lead to unauthorized access to patient data via a read-only web application.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-16218.
What is the severity of CVE-2020-16218?
The severity of CVE-2020-16218 is low.
Which software versions are affected by CVE-2020-16218?
Patient Information Center iX (PICiX) versions B.02, C.02, and C.03 are affected by CVE-2020-16218.
What is the impact of CVE-2020-16218?
CVE-2020-16218 allows attackers to execute arbitrary code or cause a denial of service.
Is there a fix available for CVE-2020-16218?
Yes, patches and updates are available to fix CVE-2020-16218. Please refer to the vendor's website for more information.