CVE-2017-9654: High severity philips dosewise vulnerability
Published Apr 24, 2018
·Updated
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.
Affected Software
2 affected components
Philips DoseWise=1.1.7.333
Philips DoseWise=2.1.1.3069
Event History
Apr 24, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9654?
CVE-2017-9654 has a CVSS v3 base score of 6.5, indicating it is a medium severity vulnerability.
2
How do I fix CVE-2017-9654?
To mitigate CVE-2017-9654, it is recommended to upgrade to a version of Philips DoseWise that does not store login credentials in clear text.
3
What versions of Philips DoseWise are affected by CVE-2017-9654?
CVE-2017-9654 affects Philips DoseWise versions 1.1.7.333 and 2.1.1.3069.
4
What type of data is exposed by CVE-2017-9654?
CVE-2017-9654 exposes login credentials stored in clear text within backend system files.
5
Is user interaction required to exploit CVE-2017-9654?
No, user interaction is not required to exploit CVE-2017-9654 as it can be accessed remotely.