ICSMA-19-297-01
·
Published 2019-10-24
·
View on CISA ICS-CERT ↗
Philips IntelliSpace Perinatal
CVSS 6.1
MEDIUM
Risk Summary
Successful exploitation of this vulnerability may allow an attacker unauthorized access to system resources, including access to execute software or to view/update files, directories, or system configuration. This could impact confidentiality and integrity of the system and application. If a user has opted to install the Document Export (DOX) function on the application server, information at risk of exposure may also include protected health information (PHI).
CVEs (1)
Remediations
- Philips has identified the following guidance and controlling risk mitigations:
- Philips will update IntelliSpace Perinatal documentation to provide clear guidance on the above mitigations. This documentation is available to users on Philips InCenter.
- Philips will be further assessing options for remediation in the next minor product update, which is planned for the end of 2020.
- Users with questions about their specific IntelliSpace Perinatal product should contact a Philips service support team.
- The Philips advisory is available at the following URL: http://www.philips.com/productsecurity
- Where additional information is needed, follow this link to existing cybersecurity in medical device guidance issued by the FDA.
Affected Vendors
Philips
Affected Products (1)
Philips
·
IntelliSpace Perinatal
<= K
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more