Skip to main content

Vendor/product archive

philips / e-alert_firmware CVEs

Beta · best-effort

10 CVEs tagged to philips / e-alert_firmware2 Critical, 5 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2018-8856

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-8854

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or amount of resources requested or influenced by an actor, whi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8852

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the oppo…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-8850

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to craft the input in a form that is not exp…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-8848

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8846

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in outpu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8844

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request wa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8842

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be s…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-14803

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that could allow attackers to obtain extraneous p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1