Philips PageWriter ECG Buffer Overflow Vulnerabilities
Philips Healthcare has released details of two buffer overflow vulnerabilities affecting a number of their PageWriter electrocardiogram (ECG) diagnostic products. They claim that an attacker with physical access to an affected device could modify system settings or access sensitive data.
Summary
Philips Healthcare has released details of two buffer overflow vulnerabilities affecting a number of their PageWriter electrocardiogram (ECG) diagnostic products. They claim that an attacker with physical access to an affected device could modify system settings or access sensitive data.
Affected platforms
The following platforms are known to be affected:
- Philips PageWriter - TC10, TC20, TC30, TC50, and TC70 series
Threat details
The vulnerabilities are a result of PageWriter systems not properly sanitising input data. If a user passes specially crafted inputs to an affected system, the system will attempt to execute them as commands, typically resulting in a buffer overflow .
For further information:
Remediation steps
CVE Vulnerabilities
Last edited: 29 June 2021 12:01 pm