Vulnerabilidades en Philips

88 resultados
Análisis Vexday

Com 88 CVEs catalogadas e nenhuma em exploração ativa no CISA KEV, a taxa de exploração confirmada da Philips está abaixo da média geral do catálogo, o que representa um perfil de risco relativamente contido no momento. Não há registros de vulnerabilidades críticas, PoCs públicas disponíveis ou novas ocorrências nos últimos 90 dias, indicando ausência de pressão ofensiva imediata. O maior score EPSS observado é 0,0625, registrado na CVE-2018-5474, que permanece como a vulnerabilidade de maior atenção no portfólio atual. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que merece atenção contínua em processos de desenvolvimento e revisão de código.

CVE-2021-27501HIGHPhilips Vue PACS Improper Adherence to Coding StandardsEPSS 0.9%CVE-2021-33024LOWPhilips Vue PACS Insufficiently Protected CredentialsEPSS 0.9%CVE-2020-27298MEDIUMPhilips Interventional Workstations OS Command InjectionEPSS 0.9%CVE-2018-8844Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a weEPSS 0.9%CVE-2021-27497MEDIUMPhilips Vue PACS Protection Mechanism FailureEPSS 0.8%CVE-2017-9658Certain 802.11 network management messages have been determined to invoke wireless access point blacklisting security defenses when not requEPSS 0.8%CVE-2017-9657Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the centraEPSS 0.8%CVE-2020-16216Philips Patient Monitoring Devices Improper Input ValidationEPSS 0.7%CVE-2021-26262MEDIUMPhilips MRI 1.5T and 3T Improper Access ControlEPSS 0.7%CVE-2021-27493MEDIUMPhilips Vue PACS EPSS 0.7%CVE-2019-6562In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placedEPSS 0.7%CVE-2020-16218Philips Patient Monitoring Devices Cross-site ScriptingEPSS 0.7%CVE-2021-33022HIGHPhilips Vue PACS Cleartext Transmission of Sensitive InformationEPSS 0.6%CVE-2018-7498In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrityEPSS 0.6%CVE-2021-33020HIGHPhilips Vue PACS Use of a Key Past its Expiration DateEPSS 0.6%CVE-2020-16200MEDIUMPhilips Clinical Collaboration Platform Algorithm DowngradeEPSS 0.6%CVE-2020-16224Philips Patient Monitoring Devices Improper Handling of Length Parameter InconsistencyEPSS 0.6%CVE-2020-16214Philips Patient Monitoring Devices Improper Neutralization of Formula Elements in a CSV FileEPSS 0.6%CVE-2018-8842Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext iEPSS 0.6%CVE-2020-16198MEDIUMPhilips Clinical Collaboration Platform Protection Mechanism FailureEPSS 0.6%