First published: Fri Sep 11 2020(Updated: )
In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions N and prior, the software does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a compromised certificate.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Patient Information Center Ix | =b.02 | |
Philips Patient Information Center Ix | =c.02 | |
Philips Patient Information Center Ix | =c.03 | |
Philips Performancebridge Focal Point | =a.01 | |
Philips Intellivue Mp2-mp90 Firmware | ||
Philips Intellivue Mp2-mp90 | =n | |
Philips Intellivue Mx100 Firmware | ||
Philips Intellivue Mx100 | ||
Philips Intellivue Mx400 Firmware | ||
Philips Intellivue Mx400 | ||
Philips Intellivue Mx850 Firmware | ||
Philips Intellivue Mx850 | ||
Philips Intellivue X2 Firmware | ||
Philips Intellivue X2 | =n | |
Philips Intellivue X3 Firmware | ||
Philips Intellivue X3 | =n | |
Philips Intellivue Mx800 Firmware | ||
Philips Intellivue Mx800 | ||
Philips Intellivue Mx750 Firmware | ||
Philips Intellivue Mx750 | ||
Philips Intellivue Mx700 Firmware | ||
Philips Intellivue Mx700 | ||
Philips Intellivue Mx600 Firmware | ||
Philips Intellivue Mx600 | ||
Philips Intellivue Mx550 Firmware | ||
Philips Intellivue Mx550 | ||
All of | ||
Philips Intellivue Mp2-mp90 Firmware | ||
Philips Intellivue Mp2-mp90 | =n | |
All of | ||
Philips Intellivue Mx100 Firmware | ||
Philips Intellivue Mx100 | ||
All of | ||
Philips Intellivue Mx400 Firmware | ||
Philips Intellivue Mx400 | ||
All of | ||
Philips Intellivue Mx850 Firmware | ||
Philips Intellivue Mx850 | ||
All of | ||
Philips Intellivue X2 Firmware | ||
Philips Intellivue X2 | =n | |
All of | ||
Philips Intellivue X3 Firmware | ||
Philips Intellivue X3 | =n | |
All of | ||
Philips Intellivue Mx800 Firmware | ||
Philips Intellivue Mx800 | ||
All of | ||
Philips Intellivue Mx750 Firmware | ||
Philips Intellivue Mx750 | ||
All of | ||
Philips Intellivue Mx700 Firmware | ||
Philips Intellivue Mx700 | ||
All of | ||
Philips Intellivue Mx600 Firmware | ||
Philips Intellivue Mx600 | ||
All of | ||
Philips Intellivue Mx550 Firmware | ||
Philips Intellivue Mx550 |
Philips released the following versions to remediate reported vulnerabilities: * Patient Information Center iX (PICiX) Version C.03 * PerformanceBridge Focal Point * IntelliVue Patient Monitors Versions N.00 and N.01 * IntelliVue Patient Monitors Version M.04: Contact a Philips service support team https://www.usa.philips.com/healthcare/solutions/customer-service-solutions for an upgrade path * Certificate revocation within the system was implemented for PIC iX and Performance Bridge FocalPoint in 2023. The implementation of the IntelliVue Patient Monitors will be completed in Q3 of 2024.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-16228.
The severity of CVE-2020-16228 is medium with a severity value of 6.4.
The software versions affected by CVE-2020-16228 are Philips Patient Information Center iX B.02, C.02, C.03, PerformanceBridge Focal Point A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior.
The vulnerability type of CVE-2020-16228 is CWE-299.
To fix CVE-2020-16228, it is recommended to update to the latest version of the affected software or apply the necessary patches and mitigations recommended by the vendor.