Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-13530


Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). An attacker can use these credentials to login via ftp and upload a malicious firmware.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.2, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 19 products from philips, from philips, from philips and 16 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2019, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2019-09-12T20:15:11.647

Last Modified

2024-11-21T04:25:05.213

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-259
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System philips intellivue_mp_monitors_mp20-mp90_firmware a.03.09 Yes
Hardware philips m80010a a No
Hardware philips m8001a a No
Hardware philips m8002a a No
Hardware philips m8003a a No
Hardware philips m8004a a No
Hardware philips m8005a a No
Hardware philips m8007a a No
Hardware philips m8008a a No
Operating System philips intellivue_mp_monitors_mp5\/5sc_firmware a.03.09 Yes
Hardware philips m8105a a No
Hardware philips m8105as a No
Operating System philips intellivue_mp_monitors_mp2\/x2_firmware a01.09 Yes
Hardware philips m3002a b No
Hardware philips m8102a b No
Operating System philips intellivue_mp_monitors_mx800\/700\/600_firmware a.01.09 Yes
Hardware philips 865240 b No
Hardware philips 865241 b No
Hardware philips 865242 b No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For philips's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.