LiveActive security incident?Get immediate response
CVE Record

CVE-2018-10597: IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue...

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This CVE affects specific IntelliVue patient monitors and Avalon fetal/maternal monitors. An unauthenticated device on the same subnet could access device memory using a write-what-where condition. In clinical environments, that makes network placement and trust boundaries important, but the provided sources do not state active exploitation or a confirmed patch.

Executive priority

Prioritize this where affected monitors are deployed in active care environments. The business risk is patient-care disruption and clinical-network compromise potential, not broad internet-scale exploitation based on the supplied evidence.

Technical view

CVE-2018-10597 is mapped to CWE-287 and describes unauthenticated memory access on affected monitor revisions. The attacker must be within the same subnet and can choose a device address. The source bundle does not provide CVSS scoring, exploit evidence, or detailed remediation instructions.

Likely exposure

Exposure is most likely in healthcare networks running the listed IntelliVue MP/MX or Avalon FM monitor revisions where other devices can reach the same subnet. Direct internet exposure is not supported by the provided evidence.

Exploitation context

The CVE is not listed as KEV in the supplied bundle. No cited source here confirms active exploitation or public exploit availability. The same-subnet condition suggests insider, compromised endpoint, or poorly segmented clinical-network scenarios are the main concern.

Researcher notes

Evidence is limited to the CVE description and ICS-CERT reference in the bundle. Do not assume a vendor patch, exploit maturity, or broader product impact without consulting the advisory and vendor materials.

Mitigation direction

  • Inventory affected IntelliVue MP/MX and Avalon monitor revisions.
  • Review ICS-CERT and vendor guidance for supported remediation or updates.
  • Restrict monitor subnets to trusted clinical systems only.
  • Limit lateral movement paths into clinical monitoring networks.
  • Monitor clinical subnets for unexpected device-to-device traffic.

Validation and detection

  • Confirm model and software revision against the affected version list.
  • Map which systems share subnets with affected monitors.
  • Check whether unauthenticated systems can reach monitor network segments.
  • Review vendor or ICS-CERT guidance for remediation status.
  • Document compensating controls for any unpatched affected devices.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-287: Credential and account abuse lookup

Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2018-10597 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
ICS-CERTIntelliVue Patient Monitors, Avalon Fetal/Maternal MonitorsThe following IntelliVue Patient Monitors versions are affected: IntelliVue Patient Monitors MP Series (includingMP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, and IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only). The following Avalon Fetal/Maternal Monitors versions are affected: Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-287 · source CWE mapping

Improper Authentication

Improper Authentication represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.