PT-2018-18668 · Philips · Philips Brilliance Ct+1
Published
2018-05-04
·
Updated
2019-10-09
·
CVE-2018-8857
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Philips Brilliance CT software versions prior to 2.6.2 (Brilliance 64)
Philips Brilliance iCT software versions prior to 4.1.6
Philips Brilliance iCT SP software versions prior to 3.2.4
Philips Brilliance CT Big Bore software versions prior to 2.3.5
Description
The software contains fixed credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. An attacker could compromise these credentials and gain access to the system.
Recommendations
For Philips Brilliance CT software version 2.6.2 and prior, update to a version later than 2.6.2.
For Philips Brilliance iCT software version 4.1.6 and prior, update to a version later than 4.1.6.
For Philips Brilliance iCT SP software version 3.2.4 and prior, update to a version later than 3.2.4.
For Philips Brilliance CT Big Bore software version 2.3.5 and prior, update to a version later than 2.3.5.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Philips Brilliance Ct
Philips Brilliance Ct Big Bore