ICSMA-21-019-01
·
Published 2021-01-19
·
View on CISA ICS-CERT ↗
Philips Interventional Workstations
CVSS 6.5
MEDIUM
Risk Summary
Successful exploitation of this vulnerability makes it possible for someone within the hospital network to remotely shut down or restart the workstation. In the event the workstation is remotely shut down, physicians are still able to use diagnostic imaging from the X-ray system.
CVEs (1)
Remediations
- Philips has released a software patch to proactively address this vulnerability in the installed base and will schedule service activities with impacted users to implement the correction. As a mitigation for this vulnerability, users with expertise are advised to change the IPMI password for the workstation interface.
- Users with questions regarding specific Philips Interventional Workspot and/or installations and correction eligibility should contact a Philips service support team, regional service support, or call 1-800-722-9377 with reference to field change order (FCO) number 2019-IGTBST-014.
- Please see the Philips product security website for the Philips advisory and the latest security information for Philips products.
Affected Vendors
Philips
Affected Products (3)
Philips
·
Interventional Workspot
(Release 1.3.2 1.4.0 1.4.1 1.4.3 1.4.5)
Philips
·
ViewForum
6.3V1L10
Philips
·
Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live
1.0
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more