7.2

CVE-2019-13530

Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). An attacker can use these credentials to login via ftp and upload a malicious firmware.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Philips ≫ Intellivue Mp Monitors Mp20-mp90 Firmware Version a.03.09
   Philips ≫ M80010a Version a
   Philips ≫ M8001a Version a
   Philips ≫ M8002a Version a
   Philips ≫ M8003a Version a
   Philips ≫ M8004a Version a
   Philips ≫ M8005a Version a
   Philips ≫ M8007a Version a
   Philips ≫ M8008a Version a
Philips ≫ Intellivue Mp Monitors Mp5/5sc Firmware Version a.03.09
   Philips ≫ M8105a Version a
   Philips ≫ M8105as Version a
Philips ≫ Intellivue Mp Monitors Mp2/x2 Firmware Version a01.09
   Philips ≫ M3002a Version b
   Philips ≫ M8102a Version b
Philips ≫ Intellivue Mp Monitors Mx800/700/600 Firmware Version a.01.09
   Philips ≫ 865240 Version b
   Philips ≫ 865241 Version b
   Philips ≫ 865242 Version b
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.36% 0.681
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-259 Use of Hard-coded Password

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://www.us-cert.gov/ics/advisories/icsma-19-255-01
Third Party Advisory
US Government Resource
Mitigation