First published: Fri Aug 31 2018(Updated: )
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips E-alert Firmware | <=r2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-8852 is high with a severity value of 8.8.
CVE-2018-8852 affects Philips e-Alert Unit (non-medical device) with firmware version R2.1 and prior.
The vulnerability type of CVE-2018-8852 is session hijacking.
An attacker can exploit CVE-2018-8852 by stealing authenticated sessions without invalidating any existing session identifier.
Please refer to the official Philips website for available fixes for CVE-2018-8852.