First published: Sat Oct 05 2013(Updated: )
Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascular Monitoring 5 components, and Xper Information Management servers and workstations for Flex Cardio products before XperConnect 1.5.4.053 SP2 allows remote attackers to execute arbitrary code via a crafted HTTP request to the Connect broker on TCP port 6000.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Xper Information Management Physiomonitoring 5 | ||
Philips Xperconnect | <=1.5.4.053 | |
Philips Xper Information Management Vascular Monitoring 5 | ||
Philips Xper Flex Cardio |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2808 is classified with a critical severity due to its potential for remote code execution.
To fix CVE-2013-2808, update the affected Philips Xper software to the latest version that addresses this vulnerability.
CVE-2013-2808 affects Philips Xper Information Management Physiomonitoring 5, Vascular Monitoring 5, and related Flex Cardio products.
Yes, CVE-2013-2808 can be exploited remotely, which makes it particularly dangerous in unpatched environments.
Exploiting CVE-2013-2808 can allow attackers to execute arbitrary code and potentially gain control of the affected systems.