CVE-2020-16222: Philips Patient Monitoring Devices Improper Authentication
In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.
Other sources
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior. When an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16222?
The severity of CVE-2020-16222 is high with a severity value of 8.8.
How does CVE-2020-16222 affect Philips Patient Information Center iX?
CVE-2020-16222 affects Philips Patient Information Center iX versions B.02, C.02, and C.03.
Which versions of Philips PerformanceBridge Focal Point are affected by CVE-2020-16222?
CVE-2020-16222 affects Philips PerformanceBridge Focal Point version A.01.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-16222?
The Common Weakness Enumeration (CWE) ID for CVE-2020-16222 is 287.
Where can I find more information about CVE-2020-16222?
You can find more information about CVE-2020-16222 at the following link: https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01