Vulnerabilidades em Philips

88 resultados
Análise Vexday

Com 88 CVEs catalogadas e nenhuma em exploração ativa no CISA KEV, a taxa de exploração confirmada da Philips está abaixo da média geral do catálogo, o que representa um perfil de risco relativamente contido no momento. Não há registros de vulnerabilidades críticas, PoCs públicas disponíveis ou novas ocorrências nos últimos 90 dias, indicando ausência de pressão ofensiva imediata. O maior score EPSS observado é 0,0625, registrado na CVE-2018-5474, que permanece como a vulnerabilidade de maior atenção no portfólio atual. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que merece atenção contínua em processos de desenvolvimento e revisão de código.

CVE-2021-27501HIGHPhilips Vue PACS Improper Adherence to Coding StandardsEPSS 0.9%CVE-2020-27298MEDIUMPhilips Interventional Workstations OS Command InjectionEPSS 0.9%CVE-2021-33024LOWPhilips Vue PACS Insufficiently Protected CredentialsEPSS 0.9%CVE-2018-8844Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a weEPSS 0.9%CVE-2017-9658Certain 802.11 network management messages have been determined to invoke wireless access point blacklisting security defenses when not requEPSS 0.8%CVE-2021-27497MEDIUMPhilips Vue PACS Protection Mechanism FailureEPSS 0.8%CVE-2017-9657Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the centraEPSS 0.8%CVE-2020-16216Philips Patient Monitoring Devices Improper Input ValidationEPSS 0.7%CVE-2019-6562In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placedEPSS 0.7%CVE-2021-27493MEDIUMPhilips Vue PACS EPSS 0.7%CVE-2020-16218Philips Patient Monitoring Devices Cross-site ScriptingEPSS 0.7%CVE-2018-7498In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrityEPSS 0.6%CVE-2021-33022HIGHPhilips Vue PACS Cleartext Transmission of Sensitive InformationEPSS 0.6%CVE-2021-26262MEDIUMPhilips MRI 1.5T and 3T Improper Access ControlEPSS 0.6%CVE-2020-16200MEDIUMPhilips Clinical Collaboration Platform Algorithm DowngradeEPSS 0.6%CVE-2021-33020HIGHPhilips Vue PACS Use of a Key Past its Expiration DateEPSS 0.6%CVE-2020-16224Philips Patient Monitoring Devices Improper Handling of Length Parameter InconsistencyEPSS 0.6%CVE-2020-16214Philips Patient Monitoring Devices Improper Neutralization of Formula Elements in a CSV FileEPSS 0.6%CVE-2018-8842Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext iEPSS 0.6%CVE-2020-16198MEDIUMPhilips Clinical Collaboration Platform Protection Mechanism FailureEPSS 0.6%