Skip to main content

Philips PageWriter ECG Buffer Overflow Vulnerabilities

Philips Healthcare has released details of two buffer overflow vulnerabilities affecting a number of their PageWriter electrocardiogram (ECG) diagnostic products. They claim that an attacker with physical access to an affected device could modify system settings or access sensitive data.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Philips Healthcare has released details of two buffer overflow vulnerabilities affecting a number of their PageWriter electrocardiogram (ECG) diagnostic products. They claim that an attacker with physical access to an affected device could modify system settings or access sensitive data.


Affected platforms

The following platforms are known to be affected:

  • Philips PageWriter - TC10, TC20, TC30, TC50, and TC70 series

Threat details

The vulnerabilities are a result of PageWriter systems not properly sanitising input data. If a user passes specially crafted inputs to an affected system, the system will attempt to execute them as commands, typically resulting in a buffer overflow .

For further information:


Remediation steps

Type Step

Philips Healthcare has confirmed that an update to address these vulnerabilities is scheduled for the third quarter of 2020. Affected organisations are encouraged to contact their relevant suppliers and apply any updates as soon as they become available.

Philips has also stated that the operating system (Windows Compact Edition 5) used by PageWriter TC20, TC30, TC50 and TC70 systems is no longer supported, and encourage organisations using PageWriter TC50 and TC70 systems to update them to the latest available operating system (Windows Compact Edition 7). TC20 system will receive an operating update in the third quarter of 2020, while TC30 system will not receive an operating system update.



CVE Vulnerabilities

Last edited: 29 June 2021 12:01 pm