Vulnerability Description
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow the user to reset existing passwords.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Philips | Pagewriter Tc70 Firmware | - |
| Philips | Pagewriter Tc70 | - |
| Philips | Pagewriter Tc50 Firmware | - |
| Philips | Pagewriter Tc50 | - |
| Philips | Pagewriter Tc30 Firmware | - |
| Philips | Pagewriter Tc30 | - |
| Philips | Pagewriter Tc20 Firmware | - |
| Philips | Pagewriter Tc20 | - |
| Philips | Pagewriter Tc10 Firmware | - |
| Philips | Pagewriter Tc10 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105103Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party AdvisoryUS Government ResourceVDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
- http://www.securityfocus.com/bid/105103Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01Third Party AdvisoryUS Government ResourceVDB Entry
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityVendor Advisory
FAQ
What is CVE-2018-14801?
CVE-2018-14801 is a vulnerability with a CVSS score of 6.2 (MEDIUM). In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that ...
How severe is CVE-2018-14801?
CVE-2018-14801 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14801?
Check the references section above for vendor advisories and patch information. Affected products include: Philips Pagewriter Tc70 Firmware, Philips Pagewriter Tc70, Philips Pagewriter Tc50 Firmware, Philips Pagewriter Tc50, Philips Pagewriter Tc30 Firmware.