Philips Brilliance CT System Vulnerabilities
Philips Healthcare has released details of three vulnerabilities affecting a number of their Brilliance computed tomography (CT) scanners.
Summary
Philips Healthcare has released details of three vulnerabilities affecting a number of their Brilliance computed tomography (CT) scanners.
Threat details
An unauthenticated user on the same network could exploit these vulnerabilities to take control of an affected system. The first two vulnerabilities (CVE-2018-8853 and CVE-2018-8861) are a result of the kiosk environment (typically a Microsoft Windows system used to interface with the scanners) incorrectly assigning elevated privileges to users.
The third vulnerability (CVE-2018-8857) lies in the hard-coded credentials used by the Brilliance software for both inbound and outbound communication, as well as for data encryption. These credentials can be obtained by an attacker on the same network as the affected systems who may then use them to access these systems.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
At the time of publication, Philips Healthcare are unable to provide any specific software updates to address these vulnerabilities. Instead, they recommend affected organisations implement the following partial mitigation steps:
They have also indicated that as the MX8000 Dual EXP is end-of-life, they will not be providing any support to organisations using this product. Affected organisations are also encouraged to contact their relevant Philips Healthcare representatives using Philips InCenter for further support. |
CVE Vulnerabilities
Last edited: 14 February 2020 2:55 pm