Vulnerability in Philips Cardiographs Allows Unauthorized Access and Settings Modification
CVE-2018-14801
6.2MEDIUM
Key Information:
- Vendor
- Philips
- Vendor
- CVE Published:
- 22 August 2018
Summary
In Philips PageWriter TC series cardiographs, unauthorized users with physical access can exploit a weakness enabling them to enter the superuser password. This grants them the ability to modify device settings and reset existing passwords, posing a significant risk for unauthorized adjustments and data integrity.
Affected Version(s)
PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs All versions prior to May 2018.
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved