IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
philips intellivue_mp2_firmware - |
||
philips intellivue_x2_firmware - |
||
philips intellivue_mp30_firmware - |
||
philips intellivue_mp50_firmware - |
||
philips intellivue_mp70_firmware - |
||
philips intellivue_np90_firmware - |
||
philips intellivue_mx700_firmware - |
||
philips intellivue_mx800_firmware - |
||
philips intellivue_mx400_firmware - |
||
philips intellivue_mx450_firmware - |
||
philips intellivue_mx500_firmware - |
||
philips intellivue_mx550_firmware - |
||
philips intellivue_x3_firmware - |
||
philips intellivue_mx100_firmware - |
||
philips avalon_fetal\\/maternal_monitors_fm20_firmware - |
||
philips avalon_fetal\\/maternal_monitors_fm30_firmware - |
||
philips avalon_fetal\\/maternal_monitors_fm40_firmware - |
||
philips avalon_fetal\\/maternal_monitors_fm50_firmware - |