Vulnerability in Philips Cardiographs Allows Unauthorized Access and Settings Modification
CVE-2018-14801

6.2MEDIUM

Key Information:

Vendor
Philips
Vendor
CVE Published:
22 August 2018

Summary

In Philips PageWriter TC series cardiographs, unauthorized users with physical access can exploit a weakness enabling them to enter the superuser password. This grants them the ability to modify device settings and reset existing passwords, posing a significant risk for unauthorized adjustments and data integrity.

Affected Version(s)

PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs All versions prior to May 2018.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.