IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.

Project Subscriptions

Vendors Products
Philips Subscribe
Avalon Fetal\/maternal Monitors Fm20 Subscribe
Avalon Fetal\/maternal Monitors Fm20 Firmware Subscribe
Avalon Fetal\/maternal Monitors Fm30 Subscribe
Avalon Fetal\/maternal Monitors Fm30 Firmware Subscribe
Avalon Fetal\/maternal Monitors Fm40 Subscribe
Avalon Fetal\/maternal Monitors Fm40 Firmware Subscribe
Avalon Fetal\/maternal Monitors Fm50 Subscribe
Avalon Fetal\/maternal Monitors Fm50 Firmware Subscribe
Intellivue Mp2 Subscribe
Intellivue Mp2 Firmware Subscribe
Intellivue Mp30 Subscribe
Intellivue Mp30 Firmware Subscribe
Intellivue Mp50 Subscribe
Intellivue Mp50 Firmware Subscribe
Intellivue Mp70 Subscribe
Intellivue Mp70 Firmware Subscribe
Intellivue Mx100 Subscribe
Intellivue Mx100 Firmware Subscribe
Intellivue Mx400 Subscribe
Intellivue Mx400 Firmware Subscribe
Intellivue Mx450 Subscribe
Intellivue Mx450 Firmware Subscribe
Intellivue Mx500 Subscribe
Intellivue Mx500 Firmware Subscribe
Intellivue Mx550 Subscribe
Intellivue Mx550 Firmware Subscribe
Intellivue Mx700 Subscribe
Intellivue Mx700 Firmware Subscribe
Intellivue Mx800 Subscribe
Intellivue Mx800 Firmware Subscribe
Intellivue Np90 Subscribe
Intellivue Np90 Firmware Subscribe
Intellivue X2 Subscribe
Intellivue X2 Firmware Subscribe
Intellivue X3 Subscribe
Intellivue X3 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-2673 IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-17T02:36:04.782Z

Reserved: 2018-05-01T00:00:00

Link: CVE-2018-10601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-05T20:29:00.903

Modified: 2024-11-21T03:41:38.507

Link: CVE-2018-10601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses