Page 3 of 114 results (0.005 seconds)

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

27 Dec 2021 — Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly. Patient Information Center iX (PIC iX) Versiones C.02 y C.03, recibe entradas o datos, pero no comprueba o comprueba incorrectamente que la entrada presenta las propiedades necesarias para procesar los datos de forma segura y correcta • https://www.cisa.gov/uscert/ics/advisories/icsma-21-322-02 • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

27 Dec 2021 — The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03. El uso de una clave criptográfica embebida aumenta significativamente la posibilidad de que los datos encriptados puedan ser recuperados de Patient Information Center iX (PIC iX) Versiones B.02, C.02 y C.03 • https://www.cisa.gov/uscert/ics/advisories/icsma-21-322-02 • CWE-321: Use of Hard-coded Cryptographic Key •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

27 Dec 2021 — The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication. La ruta de acceso estándar de IntelliBridge EC 40 and 60 Hub (versiones C.00.04 y anteriores) requiere autenticación, pero el producto presenta una ruta o canal alternativo que no requiere autenticación • https://www.cisa.gov/uscert/ics/advisories/icsma-21-322-01 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

27 Dec 2021 — IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. El IntelliBridge EC 40 y 60 Hub (versiones C.00.04 y anteriores) contiene credenciales embebidas para su propia autenticación de entrada, la comunicación de salida a componentes externos o el cifrado de datos internos • https://www.cisa.gov/uscert/ics/advisories/icsma-21-322-01 • CWE-798: Use of Hard-coded Credentials •

CVSS: 6.2EPSS: 0%CPEs: 4EXPL: 0

19 Nov 2021 — Philips MRI 1.5T and MRI 3T Version 5.x.x assigns an owner who is outside the intended control sphere to a resource. Philips MRI 1.5T y MRI 3T versión 5.x.x, asigna a un recurso un propietario que está fuera de la esfera de control prevista • https://us-cert.cisa.gov/ics/advisories/icsma-21-313-01 • CWE-708: Incorrect Ownership Assignment •

CVSS: 6.2EPSS: 0%CPEs: 4EXPL: 0

19 Nov 2021 — Philips MRI 1.5T and MRI 3T Version 5.x.x exposes sensitive information to an actor not explicitly authorized to have access. Philips MRI 1.5T y MRI 3T versión 5.x.x, expone información confidencial a un actor no autorizado explícitamente a tener acceso • https://us-cert.cisa.gov/ics/advisories/icsma-21-313-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.2EPSS: 0%CPEs: 4EXPL: 0

19 Nov 2021 — Philips MRI 1.5T and MRI 3T Version 5.x.x does not restrict or incorrectly restricts access to a resource from an unauthorized actor. Philips MRI 1.5T y MRI 3T versión 5.x.x, no restringe o restringe incorrectamente el acceso a un recurso de un actor no autorizado • https://us-cert.cisa.gov/ics/advisories/icsma-21-313-01 • CWE-284: Improper Access Control •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

24 Aug 2021 — Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter. Philips Healthcare Tasy Electronic Medical Record (EMR) versión 3.06, permite una inyección SQL por medio del parámetro WAdvancedFilter/getDimensionItemsByCode FilterValue. • https://diesec.home.blog/2021/08/24/philips-tasy-emr-3-06-sql-injection-cve-2021-39375cve-2021-39376 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

24 Aug 2021 — Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter. Philips Healthcare Tasy Electronic Medical Record (EMR) versión 3.06, permite una inyección SQL por medio del parámetro CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST o CD_USUARIO_CONVENIO. • https://diesec.home.blog/2021/08/24/philips-tasy-emr-3-06-sql-injection-cve-2021-39375cve-2021-39376 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.5EPSS: 0%CPEs: 9EXPL: 0

20 Jan 2021 — Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component. Philips Interventional Workspot (versión 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.... • https://us-cert.cisa.gov/ics/advisories/icsma-21-019-01 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •