Philips IntelliBridge EC 40 and EC 80 Hub
The Philips IntelliBridge EC 40 and EC 80 Hub contain authentication and credential management vulnerabilities (CWE-798, CWE-288) that allow an attacker with network access to gain unauthorized access without valid credentials. Exploitation could allow an attacker to execute arbitrary commands, modify system configurations, and read or alter patient data stored on the hub. The hub is used to transfer medical device data between systems according to preset specifications and is not involved in active patient monitoring. Philips has not yet released patches; the vendor states a new firmware release is planned by the end of Q4 2021.
- Network access to the IntelliBridge EC 40 or EC 80 Hub
- No valid user credentials required
- Device must be reachable from attacker's network segment
Patching may require device reboot — plan for process interruption
/api/v1/advisories/0ac2c1b8-0a8a-451f-b713-df7f244230a7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.