Vulnerability Description
In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly, which can induce a denial-of-service condition through a system restart.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Philips | Patient Information Center Ix | b.02 |
| Philips | Performancebridge Focal Point | a.01 |
| Philips | Intellivue Mp2-Mp90 Firmware | - |
| Philips | Intellivue Mp2-Mp90 | n |
| Philips | Intellivue Mx100 Firmware | - |
| Philips | Intellivue Mx100 | - |
| Philips | Intellivue Mx400 Firmware | - |
| Philips | Intellivue Mx400 | - |
| Philips | Intellivue Mx850 Firmware | - |
| Philips | Intellivue Mx850 | - |
| Philips | Intellivue X2 Firmware | - |
| Philips | Intellivue X2 | n |
| Philips | Intellivue X3 Firmware | - |
| Philips | Intellivue X3 | n |
| Philips | Intellivue Mx800 Firmware | - |
| Philips | Intellivue Mx800 | - |
| Philips | Intellivue Mx750 Firmware | - |
| Philips | Intellivue Mx750 | - |
| Philips | Intellivue Mx700 Firmware | - |
| Philips | Intellivue Mx700 | - |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01Third Party AdvisoryUS Government Resource
- https://www.philips.com/productsecurity
- https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01Third Party AdvisoryUS Government Resource
- https://www.philips.com/productsecurity
FAQ
What is CVE-2020-16216?
CVE-2020-16216 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate ...
How severe is CVE-2020-16216?
CVE-2020-16216 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16216?
Check the references section above for vendor advisories and patch information. Affected products include: Philips Patient Information Center Ix, Philips Performancebridge Focal Point, Philips Intellivue Mp2-Mp90 Firmware, Philips Intellivue Mp2-Mp90, Philips Intellivue Mx100 Firmware.