CVE-2018-14801
Summary
| CVE | CVE-2018-14801 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-22 18:29:00 UTC |
| Updated | 2019-10-09 23:35:00 UTC |
| Description | In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow the user to reset existing passwords. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Philips | Pagewriter Tc10 | - | All | All | All |
| Hardware | Philips | Pagewriter Tc10 | - | All | All | All |
| Operating System | Philips | Pagewriter Tc10 Firmware | - | All | All | All |
| Operating System | Philips | Pagewriter Tc10 Firmware | - | All | All | All |
| Hardware | Philips | Pagewriter Tc20 | - | All | All | All |
| Hardware | Philips | Pagewriter Tc20 | - | All | All | All |
| Operating System | Philips | Pagewriter Tc20 Firmware | - | All | All | All |
| Operating System | Philips | Pagewriter Tc20 Firmware | - | All | All | All |
| Hardware | Philips | Pagewriter Tc30 | - | All | All | All |
| Hardware | Philips | Pagewriter Tc30 | - | All | All | All |
| Operating System | Philips | Pagewriter Tc30 Firmware | - | All | All | All |
| Operating System | Philips | Pagewriter Tc30 Firmware | - | All | All | All |
| Hardware | Philips | Pagewriter Tc50 | - | All | All | All |
| Hardware | Philips | Pagewriter Tc50 | - | All | All | All |
| Operating System | Philips | Pagewriter Tc50 Firmware | - | All | All | All |
| Operating System | Philips | Pagewriter Tc50 Firmware | - | All | All | All |
| Hardware | Philips | Pagewriter Tc70 | - | All | All | All |
| Hardware | Philips | Pagewriter Tc70 | - | All | All | All |
| Operating System | Philips | Pagewriter Tc70 Firmware | - | All | All | All |
| Operating System | Philips | Pagewriter Tc70 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Philips PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource, VDB Entry |
| Product Security | Philips | CONFIRM | www.usa.philips.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.