CVE-2017-14111
Last modified
CVE-2017-14111 is a vulnerability of currently unknown severity. The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user entitlements.. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user entitlements.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Philips | Intellispace Cardiovascular | <= 2.3.0 |
| Philips | Xcelera | <= r4.1l1 |
References
- http://www.securityfocus.com/bid/101850Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-318-01Issue Tracking, Third Party Advisory, US Government Resource
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityIssue Tracking, Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/101850Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-318-01Issue Tracking, Third Party Advisory, US Government Resource
- https://www.usa.philips.com/healthcare/about/customer-support/product-securityIssue Tracking, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14111?
How severe is CVE-2017-14111?
How do I fix CVE-2017-14111?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14103The ReadJNGImage and ReadOneJNGImage functions in coders/png…
- CVE-2017-14105HiveManager Classic through 8.1r1 allows arbitrary JSP code …
- CVE-2017-14106The tcp_disconnect function in net/ipv4/tcp.c in the Linux k…
- CVE-2017-14107The _zip_read_eocd64 function in zip_open.c in libzip before…6.5
- CVE-2017-14108libgedit.a in GNOME gedit through 3.22.1 allows remote attac…
- CVE-2017-1411IBM Security Identity Governance Virtual Appliance 5.2 throu…5.9
- CVE-2017-14113Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-14114RTPproxy through 2.2.alpha.20160822 has a NAT feature that r…
- CVE-2017-14115The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 an…
- CVE-2017-14116The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 de…
- CVE-2017-14117The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 an…
- CVE-2017-14118In the EyesOfNetwork web interface (aka eonweb) 5.1-0, modul…
Are you affected by CVE-2017-14111?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
