nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16228 CVE-2020-16228
MEDIUM
Philips Patient Monitoring Devices Improper Check for Certificate Revocation
Record summary
CVE-2020-16228 has a selected CVSS score of 6.4 (medium).
Description
In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions N and prior, the software does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a compromised certificate.
Description source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
IntelliVue X3Browse Philips / IntelliVue X3Default status: unaffected | CVE List | Through N | affected |
IntelliVue patient monitorsBrowse Philips / IntelliVue patient monitorsDefault status: unaffected | CVE List | MX100 | affected |
| MX400-MX550 | affected | ||
| MX750 | affected | ||
| MX850 | affected | ||
Patient Information Center iX (PICiX)Browse Philips / Patient Information Center iX (PICiX)Default status: unaffected | CVE List | C.02 | affected |
| C.03 | affected | ||
PerformanceBridge Focal PointBrowse Philips / PerformanceBridge Focal PointDefault status: unaffected | CVE List | A.01 | affected |
References
3us-cert.cisa.gov
https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01 philips.com
https://www.philips.com/productsecurity