CVE-2018-8844
https://notcve.org/view.php?id=CVE-2018-8844
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. La aplicación no verifica (o no puede verificar) lo suficiente si una petición consistente, válida y bien formada ha sido intencionadamente proporcionada por el usuario que envió la petición. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-8856
https://notcve.org/view.php?id=CVE-2018-8856
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. El software contiene una clave criptográfica embebida, que emplea para cifrar los datos internos. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-798: Use of Hard-coded Credentials •
CVE-2018-8846
https://notcve.org/view.php?id=CVE-2018-8846
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is then served to other users. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. El software no neutraliza (o lo hace incorrectamente) las entradas controlables por el usuario antes de colocarlas en las salidas que se emplean como página web y luego se sirven a otros usuarios. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-8850
https://notcve.org/view.php?id=CVE-2018-8850
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to craft the input in a form that is not expected by the rest of the application. This would lead to parts of the unit receiving unintended input, which may result in altered control flow, arbitrary control of a resource, or arbitrary code execution. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. El software no valida correctamente las entradas, lo que permite que un atacante manipule las entradas de forma no esperada por el resto de la aplicación. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-20: Improper Input Validation •
CVE-2018-8852
https://notcve.org/view.php?id=CVE-2018-8852
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier. Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. Al autenticar a un usuario o establecer una nueva sesión de usuario, el software proporciona al atacante la oportunidad de robar sesiones autenticadas sin invalidar cualquier identificador de sesión existente. • http://www.securityfocus.com/bid/105194 https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 https://www.usa.philips.com/healthcare/about/customer-support/product-security • CWE-384: Session Fixation •