CVE-2018-5470

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that has been identified, which may allow an authorized local user to execute arbitrary code and escalate their level of privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:philips:intellispace_portal:8.0:*:*:*:*:*:*:*
cpe:2.3:a:philips:intellispace_portal:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:08

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/103182 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/103182 - Third Party Advisory, VDB Entry
References () https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 - Third Party Advisory, US Government Resource
References () https://www.usa.philips.com/healthcare/about/customer-support/product-security - Vendor Advisory () https://www.usa.philips.com/healthcare/about/customer-support/product-security - Vendor Advisory

Information

Published : 2018-03-26 14:29

Updated : 2024-11-21 04:08


NVD link : CVE-2018-5470

Mitre link : CVE-2018-5470

CVE.ORG link : CVE-2018-5470


JSON object : View

Products Affected

philips

  • intellispace_portal
CWE
CWE-428

Unquoted Search Path or Element

CWE-426

Untrusted Search Path