SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14801

In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the…

MEDIUM 6.2EPSS 0.41%

Does this matter?

Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.

Description

In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow the user to reset existing passwords.

CVSS 3.0
6.2 MEDIUMCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.41% probability · 34th percentile
CISA KEV
Not listed
Weakness
CWE-798
Affected
philips/pagewriter tc70 firmware · philips/pagewriter tc50 firmware · philips/pagewriter tc30 firmware · philips/pagewriter tc20 firmware · philips/pagewriter tc10 firmware
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.