8.2
CVE-2018-10601
- EPSS 0.12%
- Published 05.06.2018 20:29:00
- Last modified 21.11.2024 03:41:38
- Source ics-cert@hq.dhs.gov
- Teams watchlist Login
- Open Login
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
Data is provided by the National Vulnerability Database (NVD)
Philips ≫ Intellivue Mp2 Firmware Version-
Philips ≫ Intellivue X2 Firmware Version-
Philips ≫ Intellivue Mp30 Firmware Version-
Philips ≫ Intellivue Mp50 Firmware Version-
Philips ≫ Intellivue Mp70 Firmware Version-
Philips ≫ Intellivue Np90 Firmware Version-
Philips ≫ Intellivue Mx700 Firmware Version-
Philips ≫ Intellivue Mx800 Firmware Version-
Philips ≫ Intellivue Mx400 Firmware Version-
Philips ≫ Intellivue Mx450 Firmware Version-
Philips ≫ Intellivue Mx500 Firmware Version-
Philips ≫ Intellivue Mx550 Firmware Version-
Philips ≫ Intellivue X3 Firmware Version-
Philips ≫ Intellivue Mx100 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.12% | 0.282 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.2 | 1.6 | 6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H
|
nvd@nist.gov | 5.4 | 5.5 | 6.4 |
AV:A/AC:M/Au:N/C:P/I:P/A:P
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.