#VU23765 Inadequate Encryption Strength in Philips products - CVE-2019-18263 

 

#VU23765 Inadequate Encryption Strength in Philips products - CVE-2019-18263

Published: December 20, 2019


Vulnerability identifier: #VU23765
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-18263
CWE-ID: CWE-326
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Veradius Unity
BV Pulsera
BV Endura
Software vendor:
Philips

Description

The vulnerability allows a remote attacker to compromise the management interface of the front end router.

The vulnerability exists due to the router software uses an encryption scheme that is not strong enough for the level of protection required. A remote attacker on the local network can compromise the management interface of the front end router impacting the availability of data transfer via wireless communication.

This vulnerability affects the following products:

  • Veradius Unity with wireless option (shipped between 2016-August 2018)
  • Veradius Unity with ViewForum option (shipped between 2016-August 2018)
  • Pulsera and Endura with wireless option (shipped between 26-June-2017 through 07-August 2018)
  • Pulsera and Endura with ViewForum option (shipped between 26-June-2017 through 07-August 2018)

Remediation

Install updates from vendor's website.

External links