Banner Disclosure Vulnerability in Philips e-Alert Unit
CVE-2018-14803

5.3MEDIUM

Key Information:

Vendor
Philips
Vendor
CVE Published:
26 September 2018

Summary

The Philips e-Alert Unit, specifically Version R2.1 and earlier, contains a banner disclosure vulnerability that could expose sensitive product information to potential attackers. This vulnerability enables unauthorized access to crucial details such as the operating system and software components via the HTTP response header, which is ordinarily not disclosed. This information can assist cybercriminals in crafting more targeted attacks.

Affected Version(s)

e-Alert Unit (non-medical device) R2.1 and prior

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.