Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPhilips Intellispace Portal
APPPhilips8.09.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2018-5468CRITICAL9.8PL ✓same product
Philips Intellispace Portal — nieautoryzowany dostęp przez remote desktop (RCE)
CVE-2018-5474CRITICAL9.8PL ✓same product
RCE w Philips Intellispace Portal — brak walidacji danych wejściowych
CVE-2017-0199HIGH7.8⚠ KEVsame product
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Micros...
CVE-2017-0143HIGH8.8⚠ KEVsame product
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8....
CVE-2018-5462HIGH7.5same product
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulner...