CVE-2018-14801
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the…
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow the user to reset existing passwords.
- CVSS 3.0
- 6.2 MEDIUMCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- philips/pagewriter tc70 firmware · philips/pagewriter tc50 firmware · philips/pagewriter tc30 firmware · philips/pagewriter tc20 firmware · philips/pagewriter tc10 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/105103Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party Advisory, US Government Resource, VDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
- http://www.securityfocus.com/bid/105103Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party Advisory, US Government Resource, VDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.