← Back to home
ICSMA-18-025-01  ·  Published 2018-01-25  ·  View on CISA ICS-CERT ↗

Philips IntelliSpace Cardiovascular System Vulnerability

CVSS 6.7 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information stored on the system and modify this information.

CVEs (1)

Remediations

  • Philips is adding an additional configuration option to ISCV 3.1. The option to not use Windows authentication when communicating with an EMR in KIOSK mode will become available in this release. Philips is in the process of releasing this version in the coming months.
  • Users with questions regarding their specific IntelliSpace Cardiovascular installations are advised by Philips to contact their local Philips service support team or their regional service support. Philips' contact information is available at the following location: http://www.usa.philips.com/healthcare/solutions/customer-service-solutions
  • Please see the Philips product security web site for the latest security information for Philips products: https://www.philips.com/productsecurity

Affected Vendors

Phillips

Affected Products (1)

Phillips · IntelliSpace Cardiovascular <= 2.3.0

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more