CVE-2018-10601

HIGHCVSS 8.2/10EPSS 0.37%

Last modified

CVE-2018-10601 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.

Description

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.

Metrics

CVSS 3.1
8.2/10

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H

EPSS Probability
0.37%

28.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PhilipsIntellivue Mp2 FirmwareAll versions
PhilipsIntellivue X2 FirmwareAll versions
PhilipsIntellivue Mp30 FirmwareAll versions
PhilipsIntellivue Mp50 FirmwareAll versions
PhilipsIntellivue Mp70 FirmwareAll versions
PhilipsIntellivue Np90 FirmwareAll versions
PhilipsIntellivue Mx700 FirmwareAll versions
PhilipsIntellivue Mx800 FirmwareAll versions
PhilipsIntellivue Mx400 FirmwareAll versions
PhilipsIntellivue Mx450 FirmwareAll versions
PhilipsIntellivue Mx500 FirmwareAll versions
PhilipsIntellivue Mx550 FirmwareAll versions
PhilipsIntellivue X3 FirmwareAll versions
PhilipsIntellivue Mx100 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm20 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm30 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm40 FirmwareAll versions
PhilipsAvalon Fetal\/Maternal Monitors Fm50 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-10601?
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
How severe is CVE-2018-10601?
CVE-2018-10601 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.37% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10601?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-10601?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST