PT-2018-18657 · Philips · Philips E-Alert Unit

Publicado

2018-09-26

·

Atualizado

2019-10-09

·

CVE-2018-8844

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Philips e-Alert Unit (non-medical device) versions R2.1 and prior
Description The web application of the Philips e-Alert Unit does not sufficiently verify whether a request was intentionally provided by the user who submitted it, which can lead to potential issues.
Recommendations For versions R2.1 and prior, consider implementing additional request validation mechanisms to ensure that only well-formed and valid requests are processed by the web application. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-8844

Produtos afetados

Philips E-Alert Unit