CVE-2019-13534
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-494
- Affected
- philips/intellivue mp monitors mp20-mp90 firmware · philips/intellivue mp monitors mp5\/5sc firmware · philips/intellivue mp monitors mp2\/x2 firmware · philips/intellivue mp monitors mx800\/700\/600 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.us-cert.gov/ics/advisories/icsma-19-255-01Mitigation, Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-19-255-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.