IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Philips
Subscribe
|
Avalon Fetal\/maternal Monitors Fm20
Subscribe
Avalon Fetal\/maternal Monitors Fm20 Firmware
Subscribe
Avalon Fetal\/maternal Monitors Fm30
Subscribe
Avalon Fetal\/maternal Monitors Fm30 Firmware
Subscribe
Avalon Fetal\/maternal Monitors Fm40
Subscribe
Avalon Fetal\/maternal Monitors Fm40 Firmware
Subscribe
Avalon Fetal\/maternal Monitors Fm50
Subscribe
Avalon Fetal\/maternal Monitors Fm50 Firmware
Subscribe
Intellivue Mp2
Subscribe
Intellivue Mp2 Firmware
Subscribe
Intellivue Mp30
Subscribe
Intellivue Mp30 Firmware
Subscribe
Intellivue Mp50
Subscribe
Intellivue Mp50 Firmware
Subscribe
Intellivue Mp70
Subscribe
Intellivue Mp70 Firmware
Subscribe
Intellivue Mx100
Subscribe
Intellivue Mx100 Firmware
Subscribe
Intellivue Mx400
Subscribe
Intellivue Mx400 Firmware
Subscribe
Intellivue Mx450
Subscribe
Intellivue Mx450 Firmware
Subscribe
Intellivue Mx500
Subscribe
Intellivue Mx500 Firmware
Subscribe
Intellivue Mx550
Subscribe
Intellivue Mx550 Firmware
Subscribe
Intellivue Mx700
Subscribe
Intellivue Mx700 Firmware
Subscribe
Intellivue Mx800
Subscribe
Intellivue Mx800 Firmware
Subscribe
Intellivue Np90
Subscribe
Intellivue Np90 Firmware
Subscribe
Intellivue X2
Subscribe
Intellivue X2 Firmware
Subscribe
Intellivue X3
Subscribe
Intellivue X3 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-2673 | IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSMA-18-156-01 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-17T02:36:04.782Z
Reserved: 2018-05-01T00:00:00
Link: CVE-2018-10601
No data.
Status : Modified
Published: 2018-06-05T20:29:00.903
Modified: 2024-11-21T03:41:38.507
Link: CVE-2018-10601
No data.
OpenCVE Enrichment
No data.
EUVD