PT-2019-15295 · Philips · Philips Intellibridge Ec40+1
Publicado
2019-11-25
·
Atualizado
2019-12-18
·
CVE-2019-18241
CVSS v2.0
3.3
Baixa
| Vetor | AV:A/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Philips IntelliBridge EC40 versions all
Philips IntelliBridge EC80 versions all
Philips IntelliBridge EC40 Hub versions all
Philips IntelliBridge EC80 Hub versions all
Description
The issue concerns the SSH server configuration in the affected products, which allows weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session, potentially gaining unauthorized access to the hub.
Recommendations
For Philips IntelliBridge EC40, consider disabling the use of weak ciphers in the SSH server configuration until a patch is available.
For Philips IntelliBridge EC80, consider disabling the use of weak ciphers in the SSH server configuration until a patch is available.
For Philips IntelliBridge EC40 Hub, restrict access to the SSH server to minimize the risk of exploitation.
For Philips IntelliBridge EC80 Hub, restrict access to the SSH server to minimize the risk of exploitation.
Correção
Inadequate Encryption Strength
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Philips Intellibridge Ec40
Philips Intellibridge Ec80