In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated privileges could access folders which contain executables where authenticated users have write permissions, and could then execute arbitrary code with local administrative permissions.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01 | Third Party Advisory US Government Resource |
https://www.usa.philips.com/healthcare/about/customer-support/product-security | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-08-22 18:29
Updated : 2022-04-22 19:23
NVD link : CVE-2018-14787
Mitre link : CVE-2018-14787
CVE.ORG link : CVE-2018-14787
JSON object : View
Products Affected
philips
- xcelera
- intellispace_cardiovascular
CWE
CWE-269
Improper Privilege Management