CVE-2018-8852: High severity Philips E-alert Firmware vulnerability
Published Sep 26, 2018
·Updated
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier.
Affected Software
1 affected component
Philips E-alert Firmware<=r2.1
Event History
Sep 26, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-8852?
The severity of CVE-2018-8852 is high with a severity value of 8.8.
2
How does CVE-2018-8852 affect Philips e-Alert Unit?
CVE-2018-8852 affects Philips e-Alert Unit (non-medical device) with firmware version R2.1 and prior.
3
What is the vulnerability type of CVE-2018-8852?
The vulnerability type of CVE-2018-8852 is session hijacking.
4
How can an attacker exploit CVE-2018-8852?
An attacker can exploit CVE-2018-8852 by stealing authenticated sessions without invalidating any existing session identifier.
5
Are there any fixes available for CVE-2018-8852?
Please refer to the official Philips website for available fixes for CVE-2018-8852.