Philips e-Alert Vulnerabilities
Philips Healthcare have disclosed several vulnerabilities in their e-Alert MRI monitoring solution.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Philips Healthcare have disclosed several vulnerabilities in their e-Alert MRI monitoring solution.
Threat details
Exploitation of these vulnerabilities could allow an unauthenticated local user to execute arbitrary code, cause denial-of-service conditions, falsify user and device input or collect unit information from an affected device.
Philips Healthcare have stated there is no risk to patient safety or identifiable information.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Philips released e-Alert version R2.1 in June 2018 to address some of these vulnerabilities, and have stated that a second update will be made available before the end of 2018 to address the remaining vulnerabilities. Users and administrators are encouraged to contact their relevant providers and ensure these updates are applied as they become available. |
CVE Vulnerabilities
Last edited: 17 February 2020 12:52 pm