VulnerabilityModified
CVE-2018-14799
This can lead to buffer overflow or format string vulnerabilities.
LOW 3.7EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-119, CWE-134
- Affected
- philips/pagewriter tc70 firmware · philips/pagewriter tc50 firmware · philips/pagewriter tc30 firmware · philips/pagewriter tc20 firmware · philips/pagewriter tc10 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/105103Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party Advisory, US Government Resource, VDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
- http://www.securityfocus.com/bid/105103Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party Advisory, US Government Resource, VDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.