PT-2018-18668 · Philips · Philips Brilliance Ct+1
Publicado
2018-05-04
·
Atualizado
2019-10-09
·
CVE-2018-8857
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Philips Brilliance CT software versions prior to 2.6.2 (Brilliance 64)
Philips Brilliance iCT software versions prior to 4.1.6
Philips Brilliance iCT SP software versions prior to 3.2.4
Philips Brilliance CT Big Bore software versions prior to 2.3.5
Description
The software contains fixed credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. An attacker could compromise these credentials and gain access to the system.
Recommendations
For Philips Brilliance CT software version 2.6.2 and prior, update to a version later than 2.6.2.
For Philips Brilliance iCT software version 4.1.6 and prior, update to a version later than 4.1.6.
For Philips Brilliance iCT SP software version 3.2.4 and prior, update to a version later than 3.2.4.
For Philips Brilliance CT Big Bore software version 2.3.5 and prior, update to a version later than 2.3.5.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Philips Brilliance Ct
Philips Brilliance Ct Big Bore