CVE-2018-14799
https://notcve.org/view.php?id=CVE-2018-14799
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities. En PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs de Philips, en todas las versiones anteriores a mayo de 2018, el dispositivo PageWriter no sanea los datos introducidos por el usuario. Esto puede conducir a vulnerabilidades de desbordamiento de búfer o de cadenas de formato. • http://www.securityfocus.com/bid/105103 https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-20: Improper Input Validation CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-134: Use of Externally-Controlled Format String •
CVE-2018-14789
https://notcve.org/view.php?id=CVE-2018-14789
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary code and escalate their level of privileges. En los productos IntelliSpace Cardiovascular (ISCV) de Phillips (ISCV en versiones 2.x o anteriores y Xcelera en versiones 4.1 y anteriores), se ha identificado una vulnerabilidad de elemento o ruta de búsqueda sin entrecomillar en la que un atacante podría ejecutar código arbitrario y escalar su nivel de privilegios. • https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-428: Unquoted Search Path or Element •
CVE-2018-10599
https://notcve.org/view.php?id=CVE-2018-10599
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to read memory from an attacker-chosen device address within the same subnet. IntelliVue Patient Monitors MP Series (incluyendo MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M y (X3/MX100 solo para Rev M) y Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 con software Revisions F.0, G.0 y J.3 tienen una vulnerabilidad que permite que un atacante no autenticado lea memoria desde una dirección del dispositivo escogida por el atacante en la misma subred. • https://ics-cert.us-cert.gov/advisories/ICSMA-18-156-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-10597
https://notcve.org/view.php?id=CVE-2018-10597
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet. IntelliVue Patient Monitors MP Series (incluyendo MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M y (X3/MX100 solo para Rev M) y Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 con software Revisions F.0, G.0 y J.3 tienen una vulnerabilidad que permite que un atacante no autenticado acceda a memoria ("write-what-where") desde una dirección del dispositivo escogida por el atacante en la misma subred. • https://ics-cert.us-cert.gov/advisories/ICSMA-18-156-01 • CWE-287: Improper Authentication CWE-787: Out-of-bounds Write •
CVE-2018-10601
https://notcve.org/view.php?id=CVE-2018-10601
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow. IntelliVue Patient Monitors MP Series (incluyendo MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M y (X3/MX100 solo para Rev M) y Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 con software en Revisions F.0, G.0 y J.3 tienen una vulnerabilidad que expone un servicio "echo" por el cual un búfer enviado por el atacante a una dirección de dispositivo en la misma subred elegida por el atacante se copia a la pila sin comprobaciones de límites, lo que resulta en un desbordamiento de pila. • https://ics-cert.us-cert.gov/advisories/ICSMA-18-156-01 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •