In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated privileges could access folders which contain executables where authenticated users have write permissions, and could then execute arbitrary code with local administrative permissions.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01 | Third Party Advisory US Government Resource |
https://www.usa.philips.com/healthcare/about/customer-support/product-security | Vendor Advisory |
https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01 | Third Party Advisory US Government Resource |
https://www.usa.philips.com/healthcare/about/customer-support/product-security | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01 - Third Party Advisory, US Government Resource | |
References | () https://www.usa.philips.com/healthcare/about/customer-support/product-security - Vendor Advisory |
Information
Published : 2018-08-22 18:29
Updated : 2024-11-21 03:49
NVD link : CVE-2018-14787
Mitre link : CVE-2018-14787
CVE.ORG link : CVE-2018-14787
JSON object : View
Products Affected
philips
- intellispace_cardiovascular
- xcelera
CWE
CWE-269
Improper Privilege Management