{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2020-16220", "ASSIGNER": "ics-cert@hq.dhs.gov", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "In Patient Information Center iX (PICiX) Versions C.02, C.03, \nPerformanceBridge Focal Point Version A.01, the product receives input \nthat is expected to be well-formed (i.e., to comply with a certain \nsyntax) but it does not validate or incorrectly validates that the input\n complies with the syntax, causing the certificate enrollment service to\n crash. It does not impact monitoring but prevents new devices from \nenrolling.\n\n\n\n" } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-1286 Improper Validation of Syntactic Correctness of Input", "cweId": "CWE-1286" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Philips ", "product": { "product_data": [ { "product_name": "Patient Information Center iX (PICiX)", "version": { "version_data": [ { "version_affected": "=", "version_value": "C.02" }, { "version_affected": "=", "version_value": "C.03" } ] } }, { "product_name": "PerformanceBridge Focal Point", "version": { "version_data": [ { "version_affected": "=", "version_value": "A.01" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01", "refsource": "MISC", "name": "https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01" }, { "url": "https://www.philips.com/productsecurity", "refsource": "MISC", "name": "https://www.philips.com/productsecurity" } ] }, "generator": { "engine": "Vulnogram 0.1.0-dev" }, "source": { "discovery": "EXTERNAL" }, "work_around": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\n
As a mitigation to these vulnerabilities, Philips recommends the following:
\nUsers with questions regarding their specific Philips Patient \nInformation Center (PIC iX) and/or IntelliVue patient monitor \ninstallations and new release eligibility should contact their local Philips service support team, or regional service support, or call 1-800-722-9377.
\nPlease see the Philips product security website for the Philips advisory and the latest security information for Philips products.
\n\nPhilips released the following versions to remediate reported vulnerabilities:
\n