← Back to home
ICSMA-19-297-01  ·  Published 2019-10-24  ·  View on CISA ICS-CERT ↗

Philips IntelliSpace Perinatal

CVSS 6.1 MEDIUM

Risk Summary

Successful exploitation of this vulnerability may allow an attacker unauthorized access to system resources, including access to execute software or to view/update files, directories, or system configuration. This could impact confidentiality and integrity of the system and application. If a user has opted to install the Document Export (DOX) function on the application server, information at risk of exposure may also include protected health information (PHI).

CVEs (1)

Remediations

  • Philips has identified the following guidance and controlling risk mitigations:
  • Philips will update IntelliSpace Perinatal documentation to provide clear guidance on the above mitigations. This documentation is available to users on Philips InCenter.
  • Philips will be further assessing options for remediation in the next minor product update, which is planned for the end of 2020.
  • Users with questions about their specific IntelliSpace Perinatal product should contact a Philips service support team.
  • The Philips advisory is available at the following URL: http://www.philips.com/productsecurity
  • Where additional information is needed, follow this link to existing cybersecurity in medical device guidance issued by the FDA.

Affected Vendors

Philips

Affected Products (1)

Philips · IntelliSpace Perinatal <= K

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more