Vulnerabilities in Philips

88 results
Vexday analysis

Com 88 CVEs catalogadas e nenhuma em exploração ativa no CISA KEV, a taxa de exploração confirmada da Philips está abaixo da média geral do catálogo, o que representa um perfil de risco relativamente contido no momento. Não há registros de vulnerabilidades críticas, PoCs públicas disponíveis ou novas ocorrências nos últimos 90 dias, indicando ausência de pressão ofensiva imediata. O maior score EPSS observado é 0,0625, registrado na CVE-2018-5474, que permanece como a vulnerabilidade de maior atenção no portfólio atual. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que merece atenção contínua em processos de desenvolvimento e revisão de código.

CVE-2021-27501HIGHPhilips Vue PACS Improper Adherence to Coding StandardsEPSS 0.9%CVE-2021-33024LOWPhilips Vue PACS Insufficiently Protected CredentialsEPSS 0.9%CVE-2020-27298MEDIUMPhilips Interventional Workstations OS Command InjectionEPSS 0.9%CVE-2021-27497MEDIUMPhilips Vue PACS Protection Mechanism FailureEPSS 0.8%CVE-2018-8844Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a weEPSS 0.8%CVE-2020-16216Philips Patient Monitoring Devices Improper Input ValidationEPSS 0.7%CVE-2021-26262MEDIUMPhilips MRI 1.5T and 3T Improper Access ControlEPSS 0.7%CVE-2017-9658Certain 802.11 network management messages have been determined to invoke wireless access point blacklisting security defenses when not requEPSS 0.7%CVE-2021-27493MEDIUMPhilips Vue PACS EPSS 0.7%CVE-2019-6562In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placedEPSS 0.7%CVE-2017-9657Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the centraEPSS 0.7%CVE-2020-16218Philips Patient Monitoring Devices Cross-site ScriptingEPSS 0.7%CVE-2021-33022HIGHPhilips Vue PACS Cleartext Transmission of Sensitive InformationEPSS 0.6%CVE-2021-33020HIGHPhilips Vue PACS Use of a Key Past its Expiration DateEPSS 0.6%CVE-2020-16200MEDIUMPhilips Clinical Collaboration Platform Algorithm DowngradeEPSS 0.6%CVE-2020-16224Philips Patient Monitoring Devices Improper Handling of Length Parameter InconsistencyEPSS 0.6%CVE-2020-16214Philips Patient Monitoring Devices Improper Neutralization of Formula Elements in a CSV FileEPSS 0.6%CVE-2018-5470Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that has been identified,EPSS 0.6%CVE-2020-16198MEDIUMPhilips Clinical Collaboration Platform Protection Mechanism FailureEPSS 0.6%CVE-2021-33018HIGHPhilips Vue PACS Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.6%