CVE-2018-5470: High severity Philips IntelliSpace Portal vulnerability
Published Mar 26, 2018
·Updated
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that has been identified, which may allow an authorized local user to execute arbitrary code and escalate their level of privileges.
Affected Software
2 affected components
Philips IntelliSpace Portal=8.0
Philips IntelliSpace Portal=9.0
Event History
Mar 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5470?
CVE-2018-5470 has a medium severity rating due to its potential to allow local users to escalate privileges.
2
How do I fix CVE-2018-5470?
To fix CVE-2018-5470, ensure that all user environments have properly quoted paths in configurations.
3
What versions are affected by CVE-2018-5470?
CVE-2018-5470 affects Philips IntelliSpace Portal versions 8.0.x and 7.0.x.
4
Can CVE-2018-5470 be exploited remotely?
CVE-2018-5470 requires local access, so it cannot be exploited remotely by an unauthorized user.
5
Who is impacted by CVE-2018-5470?
Authorized local users of Philips IntelliSpace Portal may be impacted by CVE-2018-5470.