Skip to main content

Philips HDI 4000 Ultrasound Platform Vulnerability

Philips have released details of a vulnerability affecting their HDI 4000 Ultrasound system. A remote unauthenticated user could exploit this vulnerability to alter or extract sensitive information from an affected system.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Philips have released details of a vulnerability affecting their HDI 4000 Ultrasound system. A remote unauthenticated user could exploit this vulnerability to alter or extract sensitive information from an affected system.


Threat details

The vulnerability is a result of the HDI 4000 system using software built on an obsolete platform. As such, the HDI 4000 system is subject to the same unmitigated vulnerabilities as this underlying platform. An attacker with knowledge of the underlying platform could exploit any vulnerability to edit or extract information from the HDI 4000 system, including patient data.

For further information:


Remediation steps

Type Step

Philips have stated that the HDI 4000 Ultrasound product life-cycle ended in late 2013. As such, they no longer support the system in any manner. Affected organisations are encouraged to contact their appropriate suppliers in order to apply suitable alternative remediation, including:

  • applying proper network segmentation.
  • restricting access to authorised users on a least privilege approach.
  • ensuring all other connected systems are fully up-to-date.


CVE Vulnerabilities

Last edited: 14 February 2020 2:57 pm