// For flags

CVE-2019-18263

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018), Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018). The router software uses an encryption scheme that is not strong enough for the level of protection required.

Se encontró un problema en Philips Veradius Unity, Pulsera and Endura Dual WAN Router, Veradius Unity (718132) con opción inalámbrica (enviado entre 2016-Agosto 2018), Veradius Unity (718132) con opción ViewForum (enviado entre 2016-Agosto 2018) , Pulsera (718095) y Endura (718075) con opción inalámbrica (enviada entre el 26 de junio de 2017 y el 07 de agosto de 2018), Pulsera (718095) y Endura (718075) con la opción ViewForum (enviada entre el 26 de junio de 2017 y el 07 -Agosto 2018). El software del enrutador utiliza un esquema de cifrado que no es suficientemente fuerte para el nivel de protección requerido.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-10-22 CVE Reserved
  • 2019-12-20 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-326: Inadequate Encryption Strength
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Philips
Search vendor "Philips"
Veradius Unity Firmware
Search vendor "Philips" for product "Veradius Unity Firmware"
--
Affected
in Philips
Search vendor "Philips"
Veradius Unity
Search vendor "Philips" for product "Veradius Unity"
--
Safe
Philips
Search vendor "Philips"
Pulsera Firmware
Search vendor "Philips" for product "Pulsera Firmware"
--
Affected
in Philips
Search vendor "Philips"
Pulsera
Search vendor "Philips" for product "Pulsera"
--
Safe
Philips
Search vendor "Philips"
Endura Firmware
Search vendor "Philips" for product "Endura Firmware"
--
Affected
in Philips
Search vendor "Philips"
Endura
Search vendor "Philips" for product "Endura"
--
Safe