Philips Vulnerabilities and Affected Products
Vulnerabilities associated with Philips IntelliSpace Portal.
Products
Clear product- e-Alert Unit (non-medical device)9 vulnerabilities
- Philips IntelliSpace Portal9 vulnerabilities
- Hue Bridge8 vulnerabilities
- Vue PACS8 vulnerabilities
- Patient Information Center iX (PICiX)7 vulnerabilities
- Vue Motion7 vulnerabilities
- Vue MyVue7 vulnerabilities
- Vue Speech7 vulnerabilities
- Clinical Collaboration Platform5 vulnerabilities
- Brilliance CT Scanners3 vulnerabilities
- IntelliSpace Portal3 vulnerabilities
- MRI 1.5T3 vulnerabilities
- MRI 3T3 vulnerabilities
- Patient Information Center iX (PIC iX)3 vulnerabilities
- PerformanceBridge Focal Point3 vulnerabilities
- SureSigns VS43 vulnerabilities
- DoseWise Portal2 vulnerabilities
- IntelliBridge EC 40 Hub2 vulnerabilities
- IntelliBridge EC 80 Hub2 vulnerabilities
- Intellispace Cardiovascular (ISCV)2 vulnerabilities
- IntelliSpace Cardiovascular (ISCV) products2 vulnerabilities
- IntelliVue MX40 Patient Worn Monitor2 vulnerabilities
- IntelliVue patient monitors2 vulnerabilities
- PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs2 vulnerabilities
- Philips Alice 6 System2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-5454HIGH | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabled, which could allow an attacker to remotely execute arbitrary code during runtime. CWE-489Mar 26, 2018 | CVSS8.1v3.0 | EPSS3.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5468CRITICAL | Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code CWE-264Mar 26, 2018 | CVSS9.8v3.0 | EPSS4.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5472CRITICAL | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code. CWE-264Mar 26, 2018 | CVSS9.8v3.0 | EPSS4.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5458HIGH | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information. | CVSS7.5v3.0 | EPSS1.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5470HIGH | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that has been identified, which may allow an authorized local user to execute arbitrary code and escalate their level of privileges. | CVSS7.8v3.0 | EPSS0.56% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5464HIGH | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information. | CVSS7.5v3.0 | EPSS1.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5462HIGH | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information. | CVSS7.5v3.0 | EPSS1.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5466HIGH | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information. | CVSS7.5v3.0 | EPSS1.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-5474CRITICAL | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execute arbitrary code or cause the application to crash. CWE-20Mar 26, 2018 | CVSS9.8v3.0 | EPSS6.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |