CVE-2025-2229: Philips Intellispace Cardiovascular (ISCV) Use of Weak Credentials
A token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Philips Intellispace Cardiovascular (ISCV)to a version that resolves this vulnerability.Fixed in 4.2 build 20589 - Operational
For managed services users, engage the Philips-upgrade process via a local Philips sales (service) representative to upgrade the ISCV installed base to the latest available release.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2229?
CVE-2025-2229 is considered a critical vulnerability due to its potential for unauthorized access and control.
How do I fix CVE-2025-2229?
To fix CVE-2025-2229, update your Philips Intellispace Cardiovascular software to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-2229?
CVE-2025-2229 specifically affects Philips Intellispace Cardiovascular installations.
What exploit techniques are used in CVE-2025-2229?
CVE-2025-2229 can be exploited through predictable token generation using a static encryption key.
What are the potential impacts of CVE-2025-2229?
The potential impacts of CVE-2025-2229 include data breaches, unauthorized access to sensitive information, and compromised system integrity.