CVE-2020-16220
Philips Patient Monitoring Devices Improper Validation of Syntactic Correctness of Input
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Patient Information Center iX (PICiX) Versions C.02, C.03,
PerformanceBridge Focal Point Version A.01, the product receives input
that is expected to be well-formed (i.e., to comply with a certain
syntax) but it does not validate or incorrectly validates that the input
complies with the syntax, causing the certificate enrollment service to
crash. It does not impact monitoring but prevents new devices from
enrolling.
Patient Information Center iX (PICiX) Versiones B.02, C.02, C.03, PerformanceBridge Focal Point Versión A.01, Monitores de paciente IntelliVue MX100, MX400-MX850 y MP2-MP90 Versiones N y anteriores, IntelliVue X3 y X2 Versiones N y anteriores. El producto recibe una entrada que se espera que esté bien formada (es decir, que cumpla con una determinada sintaxis) pero no comprueba o comprueba incorrectamente que la entrada cumple con la sintaxis, causando que el servicio de inscripción de certificados se bloque. No impacta la supervisión, pero evita que se inscriban nuevos dispositivos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-07-31 CVE Reserved
- 2020-09-11 CVE Published
- 2023-12-13 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1286: Improper Validation of Syntactic Correctness of Input
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01 | Third Party Advisory | |
https://www.philips.com/productsecurity |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Philips Search vendor "Philips" | Patient Information Center Ix Search vendor "Philips" for product "Patient Information Center Ix" | b.02 Search vendor "Philips" for product "Patient Information Center Ix" and version "b.02" | - |
Affected
| ||||||
Philips Search vendor "Philips" | Patient Information Center Ix Search vendor "Philips" for product "Patient Information Center Ix" | c.02 Search vendor "Philips" for product "Patient Information Center Ix" and version "c.02" | - |
Affected
| ||||||
Philips Search vendor "Philips" | Patient Information Center Ix Search vendor "Philips" for product "Patient Information Center Ix" | c.03 Search vendor "Philips" for product "Patient Information Center Ix" and version "c.03" | - |
Affected
| ||||||
Philips Search vendor "Philips" | Performancebridge Focal Point Search vendor "Philips" for product "Performancebridge Focal Point" | a.01 Search vendor "Philips" for product "Performancebridge Focal Point" and version "a.01" | - |
Affected
|