VYPR

Vendor CVEs

Philips

All CVEs

125 total · sorted by risk
  • CVE-2018-8854HigSep 26, 2018
    risk 0.49cvss 7.5epss 0.03

    Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or amount of resources requested or influenced by an actor, which can be used to consume more resources than intended.

  • CVE-2018-8848HigSep 26, 2018
    risk 0.49cvss 7.5epss 0.02

    Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.

  • CVE-2018-5466HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.02

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2018-5464HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.02

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2018-5462HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.02

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2018-5458HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.01

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2017-14797HigOct 1, 2017
    risk 0.49cvss 7.5epss 0.00

    Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to…

  • CVE-2015-2884HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.01

    Philips In.Sight B120/37 allows remote attackers to obtain sensitive information via a direct request, related to yoics.net URLs, stream.m3u8 URIs, and cam_service_enable.cgi.

  • CVE-2020-7360HigAug 13, 2020
    risk 0.48cvss 7.4epss 0.00

    An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in…

  • CVE-2025-3426HigApr 7, 2025
    risk 0.47cvss epss 0.00

    We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result,…

  • CVE-2025-3425HigApr 7, 2025
    risk 0.47cvss epss 0.00

    The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the…

  • CVE-2019-13534HigSep 12, 2019
    risk 0.47cvss 7.2epss 0.01

    Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by…

  • CVE-2019-13530HigSep 12, 2019
    risk 0.47cvss 7.2epss 0.01

    Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by…

  • CVE-2017-14111HigNov 17, 2017
    risk 0.47cvss 7.2epss 0.02

    The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user…

  • CVE-2026-5441HigApr 9, 2026
    risk 0.46cvss 7.1epss 0.00

    An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the…

  • CVE-2024-9991HigOct 25, 2024
    risk 0.46cvss epss 0.00

    This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi…

  • CVE-2023-40704MedJul 18, 2024
    risk 0.44cvss 6.8epss 0.00

    The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and…

  • CVE-2020-16247MedSep 18, 2020
    risk 0.44cvss 6.8epss 0.00

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

  • CVE-2020-16212MedSep 11, 2020
    risk 0.44cvss 6.8epss 0.00

    In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on the surveillance station operates in kiosk mode, which is…

  • CVE-2019-13546MedOct 25, 2019
    risk 0.44cvss 6.8epss 0.00

    In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an authorized remote desktop session host application user to…

  • CVE-2018-14789MedAug 22, 2018
    risk 0.44cvss 6.7epss 0.00

    In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary code and escalate their level of…

  • CVE-2025-27955MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.

  • CVE-2025-27954MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.

  • CVE-2025-27953MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.

  • CVE-2021-39369MedDec 26, 2022
    risk 0.42cvss 6.5epss 0.01

    In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

  • CVE-2022-0922MedApr 1, 2022
    risk 0.42cvss 6.5epss 0.00

    The software does not perform any authentication for critical system functionality.

  • CVE-2021-27497MedApr 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

  • CVE-2021-43548MedDec 27, 2021
    risk 0.42cvss 6.5epss 0.00

    Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

  • CVE-2020-27298MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an…

  • CVE-2020-16200MedSep 18, 2020
    risk 0.42cvss 6.5epss 0.01

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available …

  • CVE-2020-16224MedSep 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data, causing the application on the …

  • CVE-2020-16216MedSep 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly validates that the input has the properties required to process…

  • CVE-2020-16228MedSep 11, 2020
    risk 0.42cvss 6.4epss 0.00

    In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions N and prior, the software does not check or incorrectly checks the revocation …

  • CVE-2019-18263MedDec 20, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura…

  • CVE-2019-18241MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.00

    In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to…

  • CVE-2017-9658MedApr 30, 2018
    risk 0.42cvss 6.5epss 0.01

    Certain 802.11 network management messages have been determined to invoke wireless access point blacklisting security defenses when not required, which can necessitate intervention by hospital staff to reset the device and reestablish a network connection to the Wi-Fi access…

  • CVE-2017-9657MedApr 30, 2018
    risk 0.42cvss 6.5epss 0.01

    Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the central monitoring station is possible. In this state, the central monitoring station can indicate the MX40 is not connected or associated to the…

  • CVE-2020-16241MedAug 21, 2020
    risk 0.41cvss 6.3epss 0.00

    Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2018-5438MedMar 20, 2018
    risk 0.41cvss 6.3epss 0.00

    Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker could reuse the session of a previously logged in user. This vulnerability exists when using ISCV together with an Electronic Medical Record (EMR) system, where…

  • CVE-2021-27493MedApr 1, 2022
    risk 0.40cvss 6.1epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

  • CVE-2021-43552MedDec 27, 2021
    risk 0.40cvss 6.1epss 0.00

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.

  • CVE-2018-8846MedSep 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is then served to other users.

  • CVE-2018-14801MedAug 22, 2018
    risk 0.40cvss 6.2epss 0.00

    In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow…

  • CVE-2018-8863MedNov 9, 2023
    risk 0.38cvss 5.9epss 0.01

    The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.

  • CVE-2021-43550MedDec 27, 2021
    risk 0.38cvss 5.9epss 0.00

    The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects the communications between Patient Information Center iX (PIC iX) Versions C.02 and C.03 and Efficia CM Series Revisions A.01 to…

  • CVE-2020-11617MedAug 31, 2020
    risk 0.38cvss 5.9epss 0.00

    The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.

  • CVE-2021-42744MedNov 19, 2021
    risk 0.36cvss 5.5epss 0.00

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2021-26262MedNov 19, 2021
    risk 0.36cvss 5.5epss 0.01

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2021-26248MedNov 19, 2021
    risk 0.36cvss 5.5epss 0.00

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2020-14518MedAug 21, 2020
    risk 0.35cvss 5.3epss 0.01

    Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.