Philips PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs (Update A)
Multiple vulnerabilities in Philips PageWriter TC10, TC20, TC30, TC50, and TC70 cardiographs allow buffer overflows and unauthorized modification of device settings. TC20, TC30, TC50, and TC70 models run the obsolete WinCE5 operating system, which is no longer supported by the OS manufacturer. TC10 and other older models have no patch available. An attacker must have physical access and administrative privileges to exploit these vulnerabilities. No public exploits currently exist, and these vulnerabilities are not remotely exploitable.
- Physical access to the cardiograph device
- Administrative or high-level user credentials
- Knowledge of the vulnerable input mechanism
Patching may require device reboot — plan for process interruption
/api/v1/advisories/2074b9f1-a7b6-4c4c-b80e-b89969a3ab6eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.