Skip to main content

Philips IntelliBridge Enterprise Information Insertion Vulnerability

Philips Healthcare has released details of a sensitive information insertion vulnerability (CWE-532) affecting their IntelliBridge Enterprise (IBE) interoperability system. They claim that a remote authenticated attacker could exploit this vulnerability to access and affected organisation's electronic medical records or clinical information systems.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Philips Healthcare has released details of a sensitive information insertion vulnerability (CWE-532) affecting their IntelliBridge Enterprise (IBE) interoperability system. They claim that a remote authenticated attacker could exploit this vulnerability to access and affected organisation's electronic medical records or clinical information systems.


Affected platforms

The following platforms are known to be affected:

  • Philips IntelliBridge Enterprise - Versions B.12 and earlier

Threat details

The vulnerability is a result of the IntelliBridge Enterprise system storing unencrypted user credentials. When other products attempt to interface with the IntelliBridge Enterprise system, these credentials are included in the plain-text transaction logs, and as such can be accessed by any administrative user.

For further information:


Remediation steps

Type Step

Philips Healthcare has confirmed that IBE version B.13 will address this vulnerability and will be available Q4 2020. Affected organisations are encouraged to review Philips' advisory and apply this update as it becomes available.



CVE Vulnerabilities

Last edited: 29 June 2021 12:01 pm