CVE-2018-14799

In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities.
References
Link Resource
https://www.usa.philips.com/healthcare/about/customer-support/product-security Vendor Advisory
https://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01 Third Party Advisory US Government Resource VDB Entry
http://www.securityfocus.com/bid/105103 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:philips:pagewriter_tc70_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:philips:pagewriter_tc70:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:philips:pagewriter_tc50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:philips:pagewriter_tc50:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:philips:pagewriter_tc30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:philips:pagewriter_tc30:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:philips:pagewriter_tc20_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:philips:pagewriter_tc20:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:philips:pagewriter_tc10_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:philips:pagewriter_tc10:-:*:*:*:*:*:*:*

Information

Published : 2018-08-22 11:29

Updated : 2019-10-09 16:35


NVD link : CVE-2018-14799

Mitre link : CVE-2018-14799


JSON object : View

CWE
CWE-134

Use of Externally-Controlled Format String

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

Advertisement

dedicated server usa

Products Affected

philips

  • pagewriter_tc20
  • pagewriter_tc30_firmware
  • pagewriter_tc20_firmware
  • pagewriter_tc10
  • pagewriter_tc30
  • pagewriter_tc70
  • pagewriter_tc10_firmware
  • pagewriter_tc50
  • pagewriter_tc70_firmware
  • pagewriter_tc50_firmware