CVE-2018-8842
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The Philips e-Alert communication channel is not encrypted which could therefore lead to disclosure of personal contact information and application login credentials from within the same subnet.
Philips e-Alert Unit (dispositivo no médico), versiones R2.1 y anteriores. El software transmite datos sensibles o críticos para la seguridad en texto claro en un canal de comunicación que puede ser rastreado por actores no autorizados. El canal de comunicación de Philips e-Alert no está cifrado, lo que podría conducir, por lo tanto, a la divulgación de información personal de contacto y de las ccredenciales de inicio de sesión en la aplicación desde dentro de la misma subred.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-20 CVE Reserved
- 2018-09-26 CVE Published
- 2024-03-02 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105194 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.usa.philips.com/healthcare/about/customer-support/product-security | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Philips Search vendor "Philips" | E-alert Firmware Search vendor "Philips" for product "E-alert Firmware" | <= r2.1 Search vendor "Philips" for product "E-alert Firmware" and version " <= r2.1" | - |
Affected
|