PT-2018-18657 · Philips · Philips E-Alert Unit
Published
2018-09-26
·
Updated
2019-10-09
·
CVE-2018-8844
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Philips e-Alert Unit (non-medical device) versions R2.1 and prior
Description
The web application of the Philips e-Alert Unit does not sufficiently verify whether a request was intentionally provided by the user who submitted it, which can lead to potential issues.
Recommendations
For versions R2.1 and prior, consider implementing additional request validation mechanisms to ensure that only well-formed and valid requests are processed by the web application. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Philips E-Alert Unit