Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascular Monitoring 5 components, and Xper Information Management servers and workstations for Flex Cardio products before XperConnect 1.5.4.053 SP2 allows remote attackers to execute arbitrary code via a crafted HTTP request to the Connect broker on TCP port 6000.
2013-10-05T10:55:03.463
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | philips | xper_information_management_physiomonitoring_5 | - | Yes |
Application | philips | xperconnect | ≤ 1.5.4.053 | Yes |
Application | philips | xper_information_management_vascular_monitoring_5 | - | Yes |
Application | philips | xperconnect | ≤ 1.5.4.053 | Yes |
Hardware | philips | xper_flex_cardio | - | Yes |
Application | philips | xperconnect | ≤ 1.5.4.053 | Yes |