5.4
CVSSv2

CVE-2018-10601

Published: 05/06/2018 Updated: 10/05/2021
CVSS v2 Base Score: 5.4 | Impact Score: 6.4 | Exploitability Score: 5.5
CVSS v3 Base Score: 8.2 | Impact Score: 6 | Exploitability Score: 1.6
VMScore: 481
Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

philips intellivue_mp2_firmware -

philips intellivue_x2_firmware -

philips intellivue_mp30_firmware -

philips intellivue_mp50_firmware -

philips intellivue_mp70_firmware -

philips intellivue_np90_firmware -

philips intellivue_mx700_firmware -

philips intellivue_mx800_firmware -

philips intellivue_mx400_firmware -

philips intellivue_mx450_firmware -

philips intellivue_mx500_firmware -

philips intellivue_mx550_firmware -

philips intellivue_x3_firmware -

philips intellivue_mx100_firmware -

philips avalon_fetal\\/maternal_monitors_fm20_firmware -

philips avalon_fetal\\/maternal_monitors_fm30_firmware -

philips avalon_fetal\\/maternal_monitors_fm40_firmware -

philips avalon_fetal\\/maternal_monitors_fm50_firmware -