VulnerabilityModified
CVE-2018-17906
Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
HIGH 8.8EPSS 0.81%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-521, CWE-306, CWE-1188
- Affected
- philips/intellispace pacs · philips/isite pacs
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/105875Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-312-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/105875Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-312-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.