CVE-2019-13546
Last modified
CVE-2019-13546 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an authorized remote desktop session host application user to break-out from the containment of the application and access unauthorized resources from the Windows operating system as the limited-access Windows user. Due to potential Windows vulnerabilities, it may be possible for additional attack methods to be used to escalate privileges on the operating system.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an authorized remote desktop session host application user to break-out from the containment of the application and access unauthorized resources from the Windows operating system as the limited-access Windows user. Due to potential Windows vulnerabilities, it may be possible for additional attack methods to be used to escalate privileges on the operating system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Philips | Intellispace Perinatal | <= k |
References
- https://www.us-cert.gov/ics/advisories/icsma-19-297-01Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-19-297-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13546?
How severe is CVE-2019-13546?
How do I fix CVE-2019-13546?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13540Delta Electronics TPEditor, Versions 1.94 and prior. Multipl…7.8
- CVE-2019-13541In Horner Automation Cscape 9.90 and prior, an improper inpu…7.8
- CVE-2019-135423S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, a…6.5
- CVE-2019-13543Medtronic Valleylab Exchange Client version 3.4 and below, V…7.5
- CVE-2019-13544Delta Electronics TPEditor, Versions 1.94 and prior. Multipl…7.8
- CVE-2019-13545In Horner Automation Cscape 9.90 and prior, improper validat…7.8
- CVE-2019-13547Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is…9.8
- CVE-2019-13548CODESYS V3 web server, all versions prior to 3.5.14.10, allo…9.8
- CVE-2019-13549Rittal Chiller SK 3232-Series web interface as built upon Ca…7.5
- CVE-2019-1355Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-13550In WebAccess, versions 8.4.1 and prior, an improper authoriz…9.8
- CVE-2019-13551Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path tra…9.8
Are you affected by CVE-2019-13546?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
