PT-2018-18668 · Philips · Philips Brilliance Ct+1

Published

2018-05-04

·

Updated

2019-10-09

·

CVE-2018-8857

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Philips Brilliance CT software versions prior to 2.6.2 (Brilliance 64) Philips Brilliance iCT software versions prior to 4.1.6 Philips Brilliance iCT SP software versions prior to 3.2.4 Philips Brilliance CT Big Bore software versions prior to 2.3.5
Description The software contains fixed credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. An attacker could compromise these credentials and gain access to the system.
Recommendations For Philips Brilliance CT software version 2.6.2 and prior, update to a version later than 2.6.2. For Philips Brilliance iCT software version 4.1.6 and prior, update to a version later than 4.1.6. For Philips Brilliance iCT SP software version 3.2.4 and prior, update to a version later than 3.2.4. For Philips Brilliance CT Big Bore software version 2.3.5 and prior, update to a version later than 2.3.5.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8857

Affected Products

Philips Brilliance Ct
Philips Brilliance Ct Big Bore