First published: Wed Sep 26 2018(Updated: )
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips E-alert Firmware | <=r2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-8848.
The severity of CVE-2018-8848 is high with a severity value of 7.5.
The affected software for CVE-2018-8848 is Philips e-Alert Unit (non-medical device) version R2.1 and prior.
CVE-2018-8848 may allow an unintended actor to gain unauthorized access to the e-Alert Unit, posing a security risk.
To fix CVE-2018-8848, it is recommended to update to a version higher than R2.1 and ensure correct permissions are set during installation.