Skip to main content

Philips Tasy EMR XSS Vulnerability

Philips have released details of a cross-site-scripting (XSS) vulnerability in their Tasy electronic medical record (EMR) system.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Philips have released details of a cross-site-scripting (XSS) vulnerability in their Tasy electronic medical record (EMR) system.


Threat details

A local, authenticated attacker could exploit this vulnerability to execute arbitrary code on an affected system.

The vulnerability appears to be a result of Tasy incorrectly neutralising inputs for data that is being served to other users. An attacker could exploit this vulnerability to alter the affected system's control flow and access sensitive information

For further information:


Remediation steps

Type Step

Philips have recommended users disable Tasy EMR access to the Internet without a virtual private network in place. Further guidance on how to do this can be found in Philips' Tasy product configuration manual.

Users and administrators are also encouraged to contact their Philips and relevant suppliers to receive tailored information and guidance.


Last edited: 14 February 2020 2:42 pm