CVE-2018-10599

UnknownEPSS 0.42%

Last modified

CVE-2018-10599 is a vulnerability of currently unknown severity. IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to read memory from an attacker-chosen device address within the same subnet.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.

Description

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to read memory from an attacker-chosen device address within the same subnet.

Metrics

EPSS Probability
0.42%

33.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PhilipsIntellivue Mp2 FirmwareAll versions
PhilipsIntellivue X2 FirmwareAll versions
PhilipsIntellivue Mp30 FirmwareAll versions
PhilipsIntellivue Mp50 FirmwareAll versions
PhilipsIntellivue Mp70 FirmwareAll versions
PhilipsIntellivue Np90 FirmwareAll versions
PhilipsIntellivue Mx700 FirmwareAll versions
PhilipsIntellivue Mx800 FirmwareAll versions
PhilipsIntellivue Mx400 FirmwareAll versions
PhilipsIntellivue Mx450 FirmwareAll versions
PhilipsIntellivue Mx500 FirmwareAll versions
PhilipsIntellivue Mx550 FirmwareAll versions
PhilipsIntellivue X3 FirmwareAll versions
PhilipsIntellivue Mx100 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm20 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm30 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm40 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm50 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-10599?
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to read memory from an attacker-chosen device address within the same subnet.
How severe is CVE-2018-10599?
Severity scoring for CVE-2018-10599 is pending analysis. The EPSS model estimates a 0.42% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10599?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-10599?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST