CVE-2020-16220 Information
Feb 14, 2021
cve
Description
Patient Information Center iX (PICiX) Versions B.02 C.02 C.03 PerformanceBridge Focal Point Version A.01 IntelliVue patient monitors MX100 MX400-MX850 and MP2-MP90 Versions N and prior IntelliVue X3 and X2 Versions N and prior. The product receives input that is expected to be well-formed (i.e. to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Reference
https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
4.3
Share on: