Junglewise Threat Intelligence

CVE-1999-0103: Philips IntelliVue Information Center iX UDP resource exhaustion

CVE-1999-0103 · Severity: medium · CVSS 5 · Published 1996-02-08

Executive brief

A vulnerability in the Philips IntelliVue Information Center iX, a real-time patient monitoring system used in healthcare, could allow an attacker to crash the device. By sending a specific sequence of network requests, an attacker can cause the system to become unresponsive, potentially disrupting critical patient monitoring services. This could impact clinical operations and the ability of medical staff to receive real-time updates on patient status.

Technical details

The Philips IntelliVue Information Center iX (Version B.02) is susceptible to a resource exhaustion vulnerability (CWE-400) triggered by UDP services such as echo and chargen. An attacker on the same local subnet can initiate multiple UDP requests in tandem to create a 'UDP packet storm' or 'UDP bomb.' This root cause involves the system's inability to properly manage these diagnostic UDP services, leading to the operating system becoming unresponsive. Successful exploitation results in a complete denial-of-service (DoS) of the monitoring application. Philips released a patch for this issue in late 2018.

Affected products

  • Philips IntelliVue Information Center iX B.02

Timeline

  • 1996-02-08: disclosed: Initial vulnerability disclosure date
  • 2018-08-30: advisory: CISA/ICS-CERT advisory published for Philips IntelliVue
  • 2018-11-30: patched: Remediation patch released by Philips

References