Vulnerabilidades em Philips
88 resultadosAnálise Vexday
Com 88 CVEs catalogadas e nenhuma em exploração ativa no CISA KEV, a taxa de exploração confirmada da Philips está abaixo da média geral do catálogo, o que representa um perfil de risco relativamente contido no momento. Não há registros de vulnerabilidades críticas, PoCs públicas disponíveis ou novas ocorrências nos últimos 90 dias, indicando ausência de pressão ofensiva imediata. O maior score EPSS observado é 0,0625, registrado na CVE-2018-5474, que permanece como a vulnerabilidade de maior atenção no portfólio atual. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que merece atenção contínua em processos de desenvolvimento e revisão de código.
CVE-2018-5474—Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to executEPSS 6.2%CVE-2018-5468—Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unaEPSS 4.6%CVE-2018-5472—Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to EPSS 4.6%CVE-2018-8850—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to crEPSS 3.8%CVE-2018-5454—Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabled, which could alloEPSS 3.5%CVE-2018-5451—In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficienEPSS 2.7%CVE-2018-8854—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or amount of resources rEPSS 2.5%CVE-2017-9656—The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a databaseEPSS 2.3%CVE-2018-8848—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an objectEPSS 2.0%CVE-2018-5462—Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an atEPSS 2.0%CVE-2018-5464—Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker toEPSS 2.0%CVE-2018-5466—Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker tEPSS 2.0%CVE-2018-8852—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, EPSS 1.9%CVE-2018-14803—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that couldEPSS 1.7%CVE-2018-8856—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encEPSS 1.4%CVE-2020-14518MEDIUMPhilips DreamMapper Insertion of Sensitive Information into Log FileEPSS 1.3%CVE-2018-5458—Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker tEPSS 1.3%CVE-2018-8846—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllEPSS 1.3%CVE-2017-9654—The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend syEPSS 1.1%CVE-2020-16239MEDIUMPhilips SureSigns VS4 Improper AuthenticationEPSS 1.0%