CVE-2018-8842
https://notcve.org/view.php?id=CVE-2018-8842
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The Philips e-Alert communication channel is not encrypted which could therefore lead to disclosure of personal contact information and application login credentials from within the same subnet. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. El software transmite datos sensibles o críticos para la seguridad en texto claro en un canal de comunicación que puede ser rastreado por actores no autorizados. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-319: Cleartext Transmission of Sensitive Information •
CVE-2018-8848
https://notcve.org/view.php?id=CVE-2018-8848
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. El software, tras su instalación, establece permisos incorrectos para un objeto que lo expone a un actor no planeado. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-276: Incorrect Default Permissions CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2018-14803
https://notcve.org/view.php?id=CVE-2018-14803
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that could allow attackers to obtain extraneous product information, such as OS and software components, via the HTTP response header that is normally not available to the attacker, but might be useful information in an attack. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. Philips e-Alert contiene una vulnerabilidad de divulgación de banner que podría permitir que los atacantes obtengan información de producto extraña, como el sistema operativo y los componentes de software, mediante la cabecera de respuesta HTTP que normalmente no está disponible para el atacante, pero que podría contener información útil en un ataque. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-8844
https://notcve.org/view.php?id=CVE-2018-8844
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. La aplicación no verifica (o no puede verificar) lo suficiente si una petición consistente, válida y bien formada ha sido intencionadamente proporcionada por el usuario que envió la petición. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-8856
https://notcve.org/view.php?id=CVE-2018-8856
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. El software contiene una clave criptográfica embebida, que emplea para cifrar los datos internos. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-798: Use of Hard-coded Credentials •