CVE-2018-10601
—CVSS 3.1
8.2 high
EPSS
<1%p30
Published
()
Modified
Description
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
- Vendors
- philips
- Products
- intellivue mp2 firmware, intellivue x2 firmware, intellivue mp30 firmware, intellivue mp50 firmware, intellivue mp70 firmware, intellivue np90 firmware, intellivue mx700 firmware, intellivue mx800 firmware, intellivue mx400 firmware, intellivue mx450 firmware, intellivue mx500 firmware, intellivue mx550 firmware
- Weakness
- CWE-121, CWE-787
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.