CRITICAL🇵🇱 Wersja polska

CVE-2018-5451

CVSS 9.8v3.0pub. 2018-03-28upd. 2024-11-21

In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or the ability to execute arbitrary code.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Philips Alice 6

    HW
    Philips
    all versions
  • Philips Alice 6 Firmware

    OS
    Philips
    ≤ r8.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2018-7498CRITICAL9.8PL ✓same product

Brak szyfrowania danych w systemie Philips Alice 6

CVE-2018-8856CRITICAL9.8PL ✓same vendor

Philips E-Alert: zakodowany na stałe klucz kryptograficzny (CWE-798)

CVE-2018-8850CRITICAL9.8PL ✓same vendor

Nieprawidłowa walidacja danych wejściowych umożliwia RCE w Philips E-Alert

CVE-2017-9656CRITICAL9.1PL ✓same vendor

Philips DoseWise Portal — zakodowane na stałe dane uwierzytelniające do bazy danych

CVE-2018-5468CRITICAL9.8PL ✓same vendor

Philips Intellispace Portal — nieautoryzowany dostęp przez remote desktop (RCE)