Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The Philips e-Alert communication channel is not encrypted which could therefore lead to disclosure of personal contact information and application login credentials from within the same subnet.
2018-09-26T19:29:00.690
2024-11-21T04:14:25.930
Modified
CVSSv3.0: 8.8 (HIGH)
AV:A/AC:L/Au:N/C:P/I:N/A:N
6.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | philips | e-alert_firmware | ≤ r2.1 | Yes |