In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated privileges could access folders which contain executables where authenticated users have write permissions, and could then execute arbitrary code with local administrative permissions.
References
Link | Resource |
---|---|
https://www.usa.philips.com/healthcare/about/customer-support/product-security | Vendor Advisory |
https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-08-22 11:29
Updated : 2022-04-22 12:23
NVD link : CVE-2018-14787
Mitre link : CVE-2018-14787
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
philips
- xcelera
- intellispace_cardiovascular