First published: Wed Sep 26 2018(Updated: )
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is then served to other users.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips E-alert Firmware | <=r2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-8846.
The severity of CVE-2018-8846 is medium (6.1).
Philips e-Alert Unit (non-medical device) Version R2.1 and prior.
The impact of CVE-2018-8846 is that user-controllable input can be mistakenly placed in the output web page served to other users.
To fix CVE-2018-8846, you should update to a version later than R2.1 of Philips e-Alert Unit software.