Remote Code Execution Vulnerability in Philips IntelliVue WLAN Portable Patient Monitors
CVE-2019-13534
Summary
Philips IntelliVue WLAN portable patient monitors are subject to a remote code execution vulnerability where the devices download source code or executables from an unverified remote location. This flaw allows attackers to execute arbitrary code on the devices, potentially compromising patient data and system integrity. The affected versions include WLAN Version A (Firmware A.03.09) and WLAN Version B (Firmware A.01.09). Protection measures should prioritize verification of code origin and integrity.
Affected Version(s)
Philips IntelliVue WLAN, portable patient monitors = WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved