First published: Fri Nov 17 2017(Updated: )
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user entitlements.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Philips IntelliSpace Cardiovascular | <=2.3.0 | |
Philips Xcelera | <=r4.1l1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14111 is classified as a high severity vulnerability due to the potential unauthorized access to sensitive authentication credentials.
To mitigate CVE-2017-14111, users should upgrade Philips IntelliSpace Cardiovascular to version 2.4.0 or later and Phillips Xcelera to version R4.1L2 or later.
CVE-2017-14111 affects Philips IntelliSpace Cardiovascular versions up to 2.3.0 and Philips Xcelera versions up to R4.1L1.
CVE-2017-14111 poses a risk of attackers gaining access to domain authentication credentials, leading to unauthorized access to the application and user data.
Currently, the best workaround for CVE-2017-14111 is to ensure proper access controls and monitor logging functions until the software is upgraded.