PT-2018-12721 · Philips · Intellispace Cardiovascular+1
Published
2018-08-22
·
Updated
2022-04-22
·
CVE-2018-14787
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IntelliSpace Cardiovascular versions 2.x and earlier
Xcelera versions 4.1 and earlier
Description
An issue exists where an attacker with escalated privileges could access folders containing executables where authenticated users have write permissions, allowing the execution of arbitrary code with local administrative permissions.
Recommendations
For IntelliSpace Cardiovascular versions 2.x and earlier, update to a version later than 2.x to resolve the issue.
For Xcelera versions 4.1 and earlier, update to a version later than 4.1 to resolve the issue.
As a temporary workaround, consider restricting write permissions for authenticated users in the affected folders to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intellispace Cardiovascular
Xcelera