CVE-2018-14789
Last modified
CVE-2018-14789 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary code and escalate their level of privileges.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary code and escalate their level of privileges.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Philips | Intellispace Cardiovascular | <= 3.1 |
| Philips | Xcelera | <= 4.1 |
References
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14789?
How severe is CVE-2018-14789?
How do I fix CVE-2018-14789?
Are you affected by CVE-2018-14789?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
