Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2017-9658

6.5 · MEDIUM
Published Apr 30, 2018 philips CWE-755 EPSS 0.84% (55th pctl)

Overview

CVE-2017-9658 is a medium-severity vulnerability affecting philips intellivue_mx40_firmware. It was published on April 30, 2018 and has a CVSS 3.0 base score of 6.5 (MEDIUM).

This vulnerability has a CVSS 3.0 base score of 6.5, rated MEDIUM. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

Certain 802.11 network management messages have been determined to invoke wireless access point blacklisting security defenses when not required, which can necessitate intervention by hospital staff to reset the device and reestablish a network connection to the Wi-Fi access point. During this state, the Philips IntelliVue MX40 Version B.06.18 can either connect to an alternative access point within signal range for association to a central monitoring station, or it can remain in local monitoring mode until the device is reset by hospital staff. CVSS v3 base score: 6.5, CVSS vector string: AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Philips has released software update, Version B.06.18, to fix the improper cleanup on thrown exception vulnerability, and implement mitigations to reduce the risk associated with the improper handling of exceptional conditions vulnerability. The software update implements messaging and alarming on the MX40 and at the central monitoring station, when the MX40 disco

Remediation

Check the references section for vendor advisories and patches from philips. Update intellivue_mx40_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
philips intellivue_mx40_firmware >= 0, < b.06.18 Affected

Frequently Asked Questions

What is CVE-2017-9658?

CVE-2017-9658 is a medium-severity vulnerability affecting philips intellivue_mx40_firmware. It was published on April 30, 2018 and has a CVSS 3.0 base score of 6.5 (MEDIUM).

How severe is CVE-2017-9658?

This vulnerability has a CVSS 3.0 base score of 6.5, rated MEDIUM. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2017-9658?

Check the references section for vendor advisories and patches from philips. Update intellivue_mx40_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2017-9658?

CyberStrike's AI-powered security agents can automatically detect CVE-2017-9658 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.