Philips Vulnerabilities and Affected Products
Vulnerabilities associated with IntelliSpace Portal.
Products
Clear product- e-Alert Unit (non-medical device)9 vulnerabilities
- Philips IntelliSpace Portal9 vulnerabilities
- Hue Bridge8 vulnerabilities
- Vue PACS8 vulnerabilities
- Patient Information Center iX (PICiX)7 vulnerabilities
- Vue Motion7 vulnerabilities
- Vue MyVue7 vulnerabilities
- Vue Speech7 vulnerabilities
- Clinical Collaboration Platform5 vulnerabilities
- Brilliance CT Scanners3 vulnerabilities
- IntelliSpace Portal3 vulnerabilities
- MRI 1.5T3 vulnerabilities
- MRI 3T3 vulnerabilities
- Patient Information Center iX (PIC iX)3 vulnerabilities
- PerformanceBridge Focal Point3 vulnerabilities
- SureSigns VS43 vulnerabilities
- DoseWise Portal2 vulnerabilities
- IntelliBridge EC 40 Hub2 vulnerabilities
- IntelliBridge EC 80 Hub2 vulnerabilities
- Intellispace Cardiovascular (ISCV)2 vulnerabilities
- IntelliSpace Cardiovascular (ISCV) products2 vulnerabilities
- IntelliVue MX40 Patient Worn Monitor2 vulnerabilities
- IntelliVue patient monitors2 vulnerabilities
- PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs2 vulnerabilities
- Philips Alice 6 System2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-3426HIGH | Use of default hardcoded credentialsWe observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to gain insights into its internal workings, which can potentially lead to the discovery of sensitive information, business logic flaws, and other vulnerabilities. Utilizing this flaw, … CWE-798Apr 7, 2025 | CVSS7.2v4.0 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3425HIGH | Unauthenticated Remote Code Execution via .NET DeserializationThe IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can potentially lead to remote code execution using deserialization. This issue affects IntelliSpace Portal: 12 and prior. CWE-502Apr 7, 2025 | CVSS7.3v4.0 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3424HIGH | 3.2.1 Arbitrary File Read in insecure .NET Remoting TCP ChannelThe IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior. CWE-22Apr 7, 2025 | CVSS7.7v4.0 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |