CVE-2020-16220: Philips Patient Monitoring Devices Improper Validation of Syntactic Correctness of Input
In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax, causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.
Other sources
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior. The product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax, causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16220?
The severity of CVE-2020-16220 is medium with a severity value of 4.3.
Which versions of Patient Information Center iX (PICiX) are affected by CVE-2020-16220?
Versions B.02, C.02, and C.03 of Patient Information Center iX (PICiX) are affected by CVE-2020-16220.
Which versions of PerformanceBridge Focal Point are affected by CVE-2020-16220?
Version A.01 of PerformanceBridge Focal Point is affected by CVE-2020-16220.
Which versions of IntelliVue patient monitors are affected by CVE-2020-16220?
Versions N and prior of IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 are affected by CVE-2020-16220.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-16220?
The Common Weakness Enumeration (CWE) ID for CVE-2020-16220 is CWE-1286.