8.7

CVE-2018-8861

Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) could enable a limited-access kiosk user or an unauthorized attacker to break-out from the containment of the kiosk environment, attain elevated privileges from the underlying Windows OS, and access unauthorized resources from the operating system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Philips ≫ Brilliance Firmware 64 Version <= 2.6.2
   Philips ≫ Brilliance 64 Version -
Philips ≫ Brilliance Ict Sp Firmware Version <= 3.2.4
   Philips ≫ Brilliance Ict Sp Version -
Philips ≫ Brilliance Ict Firmware Version <= 4.1.6
   Philips ≫ Brilliance Ict Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.326
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.7 2 6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
NIST 6.8 3.9 9.5
AV:L/AC:L/Au:N/C:C/I:C/A:P
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://www.usa.philips.com/healthcare/about/customer-support/product-security
Vendor Advisory
http://www.securityfocus.com/bid/104088
Third Party Advisory
VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSMA-18-123-01
Third Party Advisory
US Government Resource