Philips Updates
3445Warning Date
Severity Level
Warning Number
Target Sector
15 September, 2019
● Medium
2019-433
HealthCare
Description:
Philips has released security update to address multiple vulnerabilities in the following products:
- IntelliVue MP monitors MP20-MP90 (M8001A/2A/3A/4A/5A/7A/8A/10A( WLAN Version A, Firmware A.03.09
- IntelliVue MP monitors MP5/5SC (M8105A/5AS) WLAN Version A, Firmware A.03.09, Part #: M8096-67501
- IntelliVue MP monitors MP2/X2 (M8102A/M3002A) WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C)
- IntelliVue MP monitors MX800/700/600 ((865240/41/42) WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C)
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code remotely
- Exploit credentials to upload a malicious programs
Best practice and Recommendations:
The CERT team encourages users to review Philips security advisory and apply the necessary procedures according to the link below:
https://www.usa.philips.com/healthcare/about/customer-support/product-security