Vulnerability Description
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Philips | Pagewriter Tc70 Firmware | - |
| Philips | Pagewriter Tc70 | - |
| Philips | Pagewriter Tc50 Firmware | - |
| Philips | Pagewriter Tc50 | - |
| Philips | Pagewriter Tc30 Firmware | - |
| Philips | Pagewriter Tc30 | - |
| Philips | Pagewriter Tc20 Firmware | - |
| Philips | Pagewriter Tc20 | - |
| Philips | Pagewriter Tc10 Firmware | - |
| Philips | Pagewriter Tc10 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105103Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party AdvisoryUS Government ResourceVDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
- http://www.securityfocus.com/bid/105103Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party AdvisoryUS Government ResourceVDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
FAQ
What is CVE-2018-14799?
CVE-2018-14799 is a vulnerability with a CVSS score of 3.7 (LOW). In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or forma...
How severe is CVE-2018-14799?
CVE-2018-14799 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14799?
Check the references section above for vendor advisories and patch information. Affected products include: Philips Pagewriter Tc70 Firmware, Philips Pagewriter Tc70, Philips Pagewriter Tc50 Firmware, Philips Pagewriter Tc50, Philips Pagewriter Tc30 Firmware.