Vulnerabilities > CVE-2020-16224 - Improper Handling of Length Parameter Inconsistency vulnerability in Philips Patient Information Center IX C.02/C.03

047910
CVSS 6.5 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
low complexity
philips
CWE-130

Summary

In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data, causing the application on the surveillance station to restart.

Vulnerable Configurations

Part Description Count
Application
Philips
2

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Buffer Overflow via Parameter Expansion
    In this attack, the target software is given input that the attacker knows will be modified and expanded in size during processing. This attack relies on the target software failing to anticipate that the expanded data may exceed some internal limit, thereby creating a buffer overflow.