Philips kayıtları
philips üreticisine ait 115 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %1,7
- Silahlaştırılmış
- 2 · %1,7
- Pre-auth RCE
- 16
- Düzeltme kaydı olan
- %1,7
- Yayından KEV’e ortanca
- 1680 gün
Tekrar eden sınıflar
- CWE-798 Use of Hard-coded Credentials6
- CWE-122 Heap-based Buffer Overflow6
- CWE-20 Improper Input Validation6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-287 Improper Authentication4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
115 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
93Hemen | CVE-2017-0143Silahlaştırılmış | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block | Yüksek8,8 | KEV | %93,3 | 16 Mar 2017 |
91Hemen | CVE-2017-0199Silahlaştırılmış | Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windowsmicrosoft · office | Yüksek7,8 | KEV | %99,5 | 12 Nis 2017 |
41Planlayın | CVE-2018-5474İstismar yok | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to executphilips · intellispace portal · CWE-20 | Kritik9,8 | — | %6,1 | 26 Mar 2018 |
40Planlayın | CVE-2018-5472İstismar yok | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to philips · intellispace portal · CWE-264 | Kritik9,8 | — | %4,5 | 26 Mar 2018 |
40Planlayın | CVE-2018-5468İstismar yok | Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unaphilips · intellispace portal · CWE-264 | Kritik9,8 | — | %4,5 | 26 Mar 2018 |
40Planlayın | CVE-2018-8850İstismar yok | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-20 | Kritik9,8 | — | %3,8 | 26 Eyl 2018 |
40Planlayın | CVE-2018-5451İstismar yok | In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficienphilips · alice 6 firmware · CWE-287 | Kritik9,8 | — | %2,6 | 28 Mar 2018 |
39İzleyin | CVE-2015-2882İstismar yok | Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a pphilips · in.sight b120\\37 · CWE-798 | Kritik9,8 | — | %1,6 | 9 Nis 2017 |
39İzleyin | CVE-2018-8856İstismar yok | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-798 | Kritik9,8 | — | %1,4 | 26 Eyl 2018 |
39İzleyin | CVE-2021-27501İstismar yok | Philips Vue PACS Improper Adherence to Coding Standardsphilips · myvue · CWE-710 | Kritik9,8 | — | %0,9 | 1 Nis 2022 |
39İzleyin | CVE-2021-27497İstismar yok | Philips Vue PACS Protection Mechanism Failurephilips · myvue · CWE-693 | Kritik9,8 | — | %0,8 | 1 Nis 2022 |
39İzleyin | CVE-2018-7498İstismar yok | In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrityphilips · alice 6 firmware · CWE-311 | Kritik9,8 | — | %0,6 | 28 Mar 2018 |
38İzleyin | CVE-2013-2808İstismar yok | Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vasculaphilips · xper information management physiomonitoring 5 · CWE-119 | Kritik9,3 | — | %4,3 | 5 Eki 2013 |
37İzleyin | CVE-2017-9656İstismar yok | The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a databasephilips · dosewise · CWE-798 | Kritik9,1 | — | %2,3 | 24 Nis 2018 |
36İzleyin | CVE-2018-8852İstismar yok | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-384 | Yüksek8,8 | — | %1,9 | 26 Eyl 2018 |
35İzleyin | CVE-2021-39376İstismar yok | Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSISphilips · tasy electronic medical record · CWE-89 | Yüksek8,8 | — | %1,3 | 24 Ağu 2021 |
35İzleyin | CVE-2021-39375İstismar yok | Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValuphilips · tasy electronic medical record · CWE-89 | Yüksek8,8 | — | %1,3 | 24 Ağu 2021 |
35İzleyin | CVE-2017-9654İstismar yok | The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend syphilips · dosewise · CWE-312 | Yüksek8,8 | — | %1,0 | 24 Nis 2018 |
35İzleyin | CVE-2018-8844İstismar yok | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-352 | Yüksek8,8 | — | %0,9 | 26 Eyl 2018 |
35İzleyin | CVE-2018-17906İstismar yok | Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions.philips · intellispace pacs · CWE-521 | Yüksek8,8 | — | %0,8 | 19 Kas 2018 |
35İzleyin | CVE-2018-8842İstismar yok | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-319 | Yüksek8,8 | — | %0,6 | 26 Eyl 2018 |
35İzleyin | CVE-2020-16222İstismar yok | Philips Patient Monitoring Devices Improper Authenticationphilips · patient information center ix · CWE-287 | Yüksek8,8 | — | %0,5 | 11 Eyl 2020 |
35İzleyin | CVE-2026-3556İstismar yok | Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerabilityphilips · hue bridge v2 firmware · CWE-122 | Yüksek8,8 | — | %0,5 | 16 Mar 2026 |
35İzleyin | CVE-2026-3560İstismar yok | Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerabilityphilips · hue bridge v2 firmware · CWE-122 | Yüksek8,8 | — | %0,5 | 16 Mar 2026 |
35İzleyin | CVE-2021-33017İstismar yok | Philips IntelliBridge EC 40 and EC 80 Hub Authentication Bypass Using an Alternate Path or Channelphilips · intellibridge ec40 firmware · CWE-288 | Yüksek8,8 | — | %0,5 | 27 Ara 2021 |
- CVE-2017-014393Hemen
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %93microsoft · server message block16 Mar 2017
- CVE-2017-019991Hemen
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %99microsoft · office12 Nis 2017
- CVE-2018-547441Planlayın
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execut
KritikCVSS 9,8İstismar yokEPSS %6philips · intellispace portal26 Mar 2018
- CVE-2018-547240Planlayın
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to
KritikCVSS 9,8İstismar yokEPSS %5philips · intellispace portal26 Mar 2018
- CVE-2018-546840Planlayın
Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain una
KritikCVSS 9,8İstismar yokEPSS %5philips · intellispace portal26 Mar 2018
- CVE-2018-885040Planlayın
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
KritikCVSS 9,8İstismar yokEPSS %4philips · e-alert firmware26 Eyl 2018
- CVE-2018-545140Planlayın
In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficien
KritikCVSS 9,8İstismar yokEPSS %3philips · alice 6 firmware28 Mar 2018
- CVE-2015-288239İzleyin
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a p
KritikCVSS 9,8İstismar yokEPSS %2philips · in.sight b120\\379 Nis 2017
- CVE-2018-885639İzleyin
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
KritikCVSS 9,8İstismar yokEPSS %1philips · e-alert firmware26 Eyl 2018
- CVE-2021-2750139İzleyin
Philips Vue PACS Improper Adherence to Coding Standards
KritikCVSS 9,8İstismar yokEPSS %1philips · myvue1 Nis 2022
- CVE-2021-2749739İzleyin
Philips Vue PACS Protection Mechanism Failure
KritikCVSS 9,8İstismar yokEPSS %1philips · myvue1 Nis 2022
- CVE-2018-749839İzleyin
In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity
KritikCVSS 9,8İstismar yokEPSS %1philips · alice 6 firmware28 Mar 2018
- CVE-2013-280838İzleyin
Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascula
KritikCVSS 9,3İstismar yokEPSS %4philips · xper information management physiomonitoring 55 Eki 2013
- CVE-2017-965637İzleyin
The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database
KritikCVSS 9,1İstismar yokEPSS %2philips · dosewise24 Nis 2018
- CVE-2018-885236İzleyin
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
YüksekCVSS 8,8İstismar yokEPSS %2philips · e-alert firmware26 Eyl 2018
- CVE-2021-3937635İzleyin
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIS
YüksekCVSS 8,8İstismar yokEPSS %1philips · tasy electronic medical record24 Ağu 2021
- CVE-2021-3937535İzleyin
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValu
YüksekCVSS 8,8İstismar yokEPSS %1philips · tasy electronic medical record24 Ağu 2021
- CVE-2017-965435İzleyin
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend sy
YüksekCVSS 8,8İstismar yokEPSS %1philips · dosewise24 Nis 2018
- CVE-2018-884435İzleyin
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
YüksekCVSS 8,8İstismar yokEPSS %1philips · e-alert firmware26 Eyl 2018
- CVE-2018-1790635İzleyin
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions.
YüksekCVSS 8,8İstismar yokEPSS %1philips · intellispace pacs19 Kas 2018
- CVE-2018-884235İzleyin
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
YüksekCVSS 8,8İstismar yokEPSS %1philips · e-alert firmware26 Eyl 2018
- CVE-2020-1622235İzleyin
Philips Patient Monitoring Devices Improper Authentication
YüksekCVSS 8,8İstismar yokEPSS %1philips · patient information center ix11 Eyl 2020
- CVE-2026-355635İzleyin
Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1philips · hue bridge v2 firmware16 Mar 2026
- CVE-2026-356035İzleyin
Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1philips · hue bridge v2 firmware16 Mar 2026
- CVE-2021-3301735İzleyin
Philips IntelliBridge EC 40 and EC 80 Hub Authentication Bypass Using an Alternate Path or Channel
YüksekCVSS 8,8İstismar yokEPSS %0philips · intellibridge ec40 firmware27 Ara 2021