PT-2019-15295 · Philips · Philips Intellibridge Ec40+1

Published

2019-11-25

·

Updated

2019-12-18

·

CVE-2019-18241

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Philips IntelliBridge EC40 versions all Philips IntelliBridge EC80 versions all Philips IntelliBridge EC40 Hub versions all Philips IntelliBridge EC80 Hub versions all
Description The issue concerns the SSH server configuration in the affected products, which allows weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session, potentially gaining unauthorized access to the hub.
Recommendations For Philips IntelliBridge EC40, consider disabling the use of weak ciphers in the SSH server configuration until a patch is available. For Philips IntelliBridge EC80, consider disabling the use of weak ciphers in the SSH server configuration until a patch is available. For Philips IntelliBridge EC40 Hub, restrict access to the SSH server to minimize the risk of exploitation. For Philips IntelliBridge EC80 Hub, restrict access to the SSH server to minimize the risk of exploitation.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18241

Affected Products

Philips Intellibridge Ec40
Philips Intellibridge Ec80