Lucene search

K

Philips Security Vulnerabilities

cve
cve

CVE-2020-16216

In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly validates that the input has the properties required to process the data safely...

6.5CVSS

6.4AI Score

0.001EPSS

2020-09-11 02:15 PM
29
cve
cve

CVE-2020-16228

In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions N and prior, the software does not check or incorrectly checks the revocation status of a...

6.4CVSS

6.3AI Score

0.0004EPSS

2020-09-11 01:15 PM
28
cve
cve

CVE-2020-16224

In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data, causing the application on the surveillance station...

6.5CVSS

6.4AI Score

0.001EPSS

2020-09-11 02:15 PM
21
cve
cve

CVE-2020-16212

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on the surveillance station operates in kiosk mode, which is vulnerable to local...

6.8CVSS

6.3AI Score

0.001EPSS

2020-09-11 02:15 PM
28
cve
cve

CVE-2020-16220

In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the...

4.3CVSS

4.7AI Score

0.001EPSS

2020-09-11 02:15 PM
25
cve
cve

CVE-2020-16222

In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is...

8.8CVSS

8.5AI Score

0.001EPSS

2020-09-11 01:15 PM
24
cve
cve

CVE-2020-16214

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by...

5CVSS

5.1AI Score

0.001EPSS

2020-09-11 01:15 PM
27
cve
cve

CVE-2020-16218

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful exploitation could lead to unauthorized...

3.5CVSS

3.9AI Score

0.0004EPSS

2020-09-11 01:15 PM
37
cve
cve

CVE-2018-8863

The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive...

7.5CVSS

7.5AI Score

0.001EPSS

2023-11-09 11:15 PM
16
cve
cve

CVE-2021-33020

Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that...

8.2CVSS

8.2AI Score

0.002EPSS

2022-04-01 11:15 PM
82
cve
cve

CVE-2020-6007

Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code...

7.9CVSS

8AI Score

0.002EPSS

2020-01-23 10:15 PM
133
cve
cve

CVE-2021-39369

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web...

6.5CVSS

6.3AI Score

0.002EPSS

2022-12-26 06:15 AM
22
cve
cve

CVE-2019-6562

In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other...

5.4CVSS

5.4AI Score

0.001EPSS

2019-05-01 07:29 PM
28
2
cve
cve

CVE-2010-4904

SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party...

8.6AI Score

0.005EPSS

2022-10-03 04:21 PM
21
cve
cve

CVE-2013-2808

Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascular Monitoring 5 components, and Xper Information Management servers and workstations for Flex Cardio products before XperConnect 1.5.4.053 SP2 allows remote...

8.4AI Score

0.002EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2021-32966

Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP referrals, which may allow an attacker to remotely read LDAP....

7.5CVSS

7.2AI Score

0.001EPSS

2022-05-25 02:15 PM
53
4
cve
cve

CVE-2022-0922

The software does not perform any authentication for critical system...

6.5CVSS

6.7AI Score

0.0005EPSS

2022-04-01 11:15 PM
56
cve
cve

CVE-2021-33018

The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive...

7.5CVSS

7.9AI Score

0.002EPSS

2022-04-01 11:15 PM
70
cve
cve

CVE-2021-33022

Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized...

7.5CVSS

7.4AI Score

0.002EPSS

2022-04-01 11:15 PM
64
cve
cve

CVE-2021-33024

Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or...

7.5CVSS

8.1AI Score

0.002EPSS

2022-04-01 11:15 PM
52
cve
cve

CVE-2021-27497

Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the...

9.8CVSS

9.3AI Score

0.002EPSS

2022-04-01 11:15 PM
70
cve
cve

CVE-2021-27493

Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream...

6.5CVSS

6.3AI Score

0.001EPSS

2022-04-01 11:15 PM
46
cve
cve

CVE-2021-27501

Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated...

9.8CVSS

9.4AI Score

0.002EPSS

2022-04-01 11:15 PM
70
cve
cve

CVE-2021-27456

Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access...

2.4CVSS

3.8AI Score

0.001EPSS

2022-03-23 08:15 PM
61
cve
cve

CVE-2021-23173

The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive...

4.3CVSS

4.7AI Score

0.001EPSS

2022-01-10 02:10 PM
21
2
cve
cve

CVE-2021-32993

IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal...

8.8CVSS

8.7AI Score

0.001EPSS

2021-12-27 07:15 PM
28
cve
cve

CVE-2021-43552

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and...

6.1CVSS

5.5AI Score

0.0004EPSS

2021-12-27 07:15 PM
25
cve
cve

CVE-2021-33017

The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require...

8.8CVSS

8.6AI Score

0.001EPSS

2021-12-27 07:15 PM
28
cve
cve

CVE-2021-43548

Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and...

6.5CVSS

6.4AI Score

0.0005EPSS

2021-12-27 07:15 PM
23
cve
cve

CVE-2021-43550

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects the communications between Patient Information Center iX (PIC iX) Versions C.02 and C.03 and Efficia CM Series Revisions A.01 to C.0x and...

6.5CVSS

6.4AI Score

0.001EPSS

2021-12-27 07:15 PM
26
cve
cve

CVE-2021-42744

Philips MRI 1.5T and MRI 3T Version 5.x.x exposes sensitive information to an actor not explicitly authorized to have...

6.2CVSS

5.3AI Score

0.0004EPSS

2021-11-19 07:15 PM
17
cve
cve

CVE-2021-26248

Philips MRI 1.5T and MRI 3T Version 5.x.x assigns an owner who is outside the intended control sphere to a...

6.2CVSS

5.5AI Score

0.0004EPSS

2021-11-19 07:15 PM
18
cve
cve

CVE-2021-26262

Philips MRI 1.5T and MRI 3T Version 5.x.x does not restrict or incorrectly restricts access to a resource from an unauthorized...

6.2CVSS

5.4AI Score

0.0004EPSS

2021-11-19 07:15 PM
21
2
cve
cve

CVE-2021-39376

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO...

8.8CVSS

9.1AI Score

0.001EPSS

2021-08-24 01:15 PM
34
cve
cve

CVE-2021-39375

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue...

8.8CVSS

9.1AI Score

0.001EPSS

2021-08-24 01:15 PM
41
cve
cve

CVE-2020-27298

Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but...

6.5CVSS

6.5AI Score

0.001EPSS

2021-01-26 06:15 PM
21
2
cve
cve

CVE-2018-7580

Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of...

7.5CVSS

7.4AI Score

0.015EPSS

2020-12-21 09:15 PM
54
2
cve
cve

CVE-2020-16200

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available...

6.5CVSS

6.3AI Score

0.001EPSS

2020-09-18 06:15 PM
24
cve
cve

CVE-2020-16247

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the...

7.1CVSS

6.8AI Score

0.0004EPSS

2020-09-18 06:15 PM
20
cve
cve

CVE-2020-14525

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other...

3.5CVSS

3.7AI Score

0.0004EPSS

2020-09-18 06:15 PM
18
cve
cve

CVE-2020-14506

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and...

4.3CVSS

4.1AI Score

0.001EPSS

2020-09-18 06:15 PM
18
cve
cve

CVE-2020-16198

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. When an attacker claims to have a given identity, the software does not prove or insufficiently proves the claim is...

6.3CVSS

6.1AI Score

0.001EPSS

2020-09-18 06:15 PM
24
cve
cve

CVE-2020-11618

THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET...

7.8CVSS

7.5AI Score

0.001EPSS

2020-08-31 03:15 PM
20
cve
cve

CVE-2020-11617

The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the...

5.9CVSS

5.6AI Score

0.001EPSS

2020-08-31 03:15 PM
13
cve
cve

CVE-2020-16239

Philips SureSigns VS4, A.07.107 and prior. When an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is...

4.9CVSS

5AI Score

0.001EPSS

2020-08-21 01:15 PM
25
cve
cve

CVE-2020-14518

Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential...

5.3CVSS

5.2AI Score

0.001EPSS

2020-08-21 01:15 PM
22
cve
cve

CVE-2020-16237

Philips SureSigns VS4, A.07.107 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and...

2.1CVSS

3.7AI Score

0.0004EPSS

2020-08-21 01:15 PM
19
cve
cve

CVE-2020-16241

Philips SureSigns VS4, A.07.107 and prior. The software does not restrict or incorrectly restricts access to a resource from an unauthorized...

2.1CVSS

3.8AI Score

0.0004EPSS

2020-08-21 01:15 PM
30
cve
cve

CVE-2020-7360

An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was....

7.4CVSS

7.1AI Score

0.001EPSS

2020-08-13 07:15 PM
36
cve
cve

CVE-2020-14477

In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require...

4.4CVSS

4.9AI Score

0.0004EPSS

2020-06-26 05:15 PM
27
Total number of security vulnerabilities107