CISA Philips e-Alert Advisory

The Department of Homeland Security Cybersecurity & Infrastructure Security Agency (CISA) has issued a 3/29 medical advisory on the Philips e-Alert MRI system monitoring platform version 2.7 and prior. The advisory says the e-Alert is missing authentication for a critical function and successful exploitation of this vulnerability could allow an unauthorized actor to remotely shut down the system if it is on a healthcare facility’s network.

The advisory says Philips plans a new release to remediate the vulnerability before July. It gives recommendations for interim mitigation of the vulnerability.

Read more