PT-2018-18657 · Philips · Philips E-Alert Unit
Publicado
2018-09-26
·
Atualizado
2019-10-09
·
CVE-2018-8844
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Philips e-Alert Unit (non-medical device) versions R2.1 and prior
Description
The web application of the Philips e-Alert Unit does not sufficiently verify whether a request was intentionally provided by the user who submitted it, which can lead to potential issues.
Recommendations
For versions R2.1 and prior, consider implementing additional request validation mechanisms to ensure that only well-formed and valid requests are processed by the web application. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Philips E-Alert Unit