Skip to main content

Philips IntelliVue WLAN Vulnerabilities

Philips has released details of two vulnerabilities affecting their IntelliVue wireless local area network (WLAN) platform and the products that use this platform.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Philips has released details of two vulnerabilities affecting their IntelliVue wireless local area network (WLAN) platform and the products that use this platform.


Threat details

A remote authenticated user could exploit these vulnerabilities to alter system firmware. Both vulnerabilities are a result of the IntelliVue WLAN platform not properly verifying the content of firmware files or authenticating their origin. An attacker with knowledge of the target system could exploit these vulnerabilities to install their own malicious firmware over FTP.

For further information:


Remediation steps

Type Step

Philips Healthcare have stated that all IntelliVue WLAN version B variants are obsolete, and are advising affected organisations update to WLAN version C firmware variant B.00.31 and onwards.

WLAN version A variants will receive a software update via Philips' InCenter portal before the end of 2019.



CVE Vulnerabilities

Last edited: 14 February 2020 2:57 pm