Buffer Overflow and Format String Vulnerability in Philips Cardiographs
CVE-2018-14799

3.7LOW

Key Information:

Vendor
Philips
Vendor
CVE Published:
22 August 2018

Summary

The Philips PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs suffer from a vulnerability due to inadequate sanitization of user input. This flaw can be exploited to cause buffer overflow or format string issues, potentially allowing unauthorized access or manipulation of the device's functionality. Users should ensure their devices are updated to versions released after May 2018 to mitigate these risks.

Affected Version(s)

PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs All versions prior to May 2018.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.