ZeroHour

CVE-2018-10601

CVSS 3.1
8.2 high
EPSS
<1%p30
Published
()
Modified
Description

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.

Vendors
philips
Products
intellivue mp2 firmware, intellivue x2 firmware, intellivue mp30 firmware, intellivue mp50 firmware, intellivue mp70 firmware, intellivue np90 firmware, intellivue mx700 firmware, intellivue mx800 firmware, intellivue mx400 firmware, intellivue mx450 firmware, intellivue mx500 firmware, intellivue mx550 firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H

In the news

No ingested article mentions this CVE yet.