PT-2018-18657 · Philips · Philips E-Alert Unit

Published

2018-09-26

·

Updated

2019-10-09

·

CVE-2018-8844

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Philips e-Alert Unit (non-medical device) versions R2.1 and prior
Description The web application of the Philips e-Alert Unit does not sufficiently verify whether a request was intentionally provided by the user who submitted it, which can lead to potential issues.
Recommendations For versions R2.1 and prior, consider implementing additional request validation mechanisms to ensure that only well-formed and valid requests are processed by the web application. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8844

Affected Products

Philips E-Alert Unit