CVE-2021-33017: Philips IntelliBridge EC 40 and EC 80 Hub Authentication Bypass Using an Alternate Path or Channel
Published Dec 27, 2021
·Updated
The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Software
4 affected components
Philips Intellibridge Ec40 Firmware<=c.00.04
Philips IntelliBridge EC40
Philips Intellibridge Ec80 Firmware<=c.00.04
Philips IntelliBridge EC80
Event History
Dec 27, 2021
CVE Published
via MITRE·06:48 PM
Data Sourced
via MITRE·06:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33017.
2
What is the severity of CVE-2021-33017?
The severity of CVE-2021-33017 is high, with a severity value of 8.8.
3
Which products are affected by CVE-2021-33017?
The Philips IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) are affected by CVE-2021-33017.
4
What is the description of CVE-2021-33017?
CVE-2021-33017 is a vulnerability in the standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) that allows unauthorized access without authentication.
5
How can I fix CVE-2021-33017?
To fix CVE-2021-33017, it is recommended to update the firmware of the Philips IntelliBridge EC 40 and 60 Hub to version C.00.05 or later, which addresses the vulnerability.