Improper Handling of Length Parameter Inconsistency in Patient Information Center iX - CVE-2020-16224

 

Improper Handling of Length Parameter Inconsistency in Patient Information Center iX - CVE-2020-16224

Published: September 11, 2020


Vulnerability identifier: #VU46650
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-16224
CWE-ID: CWE-130
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Patient Information Center iX
Software vendor:
Philips

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the affected software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data. A remote attacker on the local network can cause the application on the surveillance station to restart.  


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links