Remote Code Execution Vulnerability in Philips IntelliVue WLAN Portable Patient Monitors
CVE-2019-13534

7.2HIGH

Key Information:

Vendor
Philips
Vendor
CVE Published:
12 September 2019

Summary

Philips IntelliVue WLAN portable patient monitors are subject to a remote code execution vulnerability where the devices download source code or executables from an unverified remote location. This flaw allows attackers to execute arbitrary code on the devices, potentially compromising patient data and system integrity. The affected versions include WLAN Version A (Firmware A.03.09) and WLAN Version B (Firmware A.01.09). Protection measures should prioritize verification of code origin and integrity.

Affected Version(s)

Philips IntelliVue WLAN, portable patient monitors = WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C)

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-13534 : Remote Code Execution Vulnerability in Philips IntelliVue WLAN Portable Patient Monitors | SecurityVulnerability.io