Vulnerability index

Browse CVEs

96 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mri 3t Firmware MEDIUM 5.5
CVE-2021-26262

Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Fix: 6.0.0+
Fix from $1,600 2021-11-19
Tasy Electronic Medical Record HIGH 8.8
CVE-2021-39375

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue paramet…

No fix yet
Fix from $1,950 2021-08-24
Tasy Electronic Medical Record HIGH 8.8
CVE-2021-39376

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_U…

No fix yet
Fix from $1,950 2021-08-24
Coronary Tools MEDIUM 6.5
CVE-2020-27298

Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), V…

Mitigation only
Fix from $1,600 2021-01-26
Hue Firmware HIGH 7.5
CVE-2018-7580

Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding…

No fix yet
Fix from $1,950 2020-12-21
Clinical Collaboration Platform HIGH 7.1
CVE-2020-16247

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors wi…

Fix: after 12.2.1
Fix from $1,950 2020-09-18
Clinical Collaboration Platform MEDIUM 6.5
CVE-2020-16200

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource…

Fix: after 12.2.1
Fix from $1,600 2020-09-18
Clinical Collaboration Platform MEDIUM 6.3
CVE-2020-16198

When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficie…

Fix: after 12.2.1
Fix from $1,600 2020-09-18
Patient Information Center Ix MEDIUM 6.8
CVE-2020-16212

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended …

Mitigation only
Fix from $1,600 2020-09-11
Patient Information Center Ix MEDIUM 6.5
CVE-2020-16216

In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the pr…

Mitigation only
Fix from $1,600 2020-09-11
Patient Information Center Ix MEDIUM 6.5
CVE-2020-16224

In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrect…

Mitigation only
Fix from $1,600 2020-09-11
Patient Information Center Ix HIGH 8.8
CVE-2020-16222

In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a g…

No fix yet
Fix from $1,950 2020-09-11
Patient Information Center Ix MEDIUM 6.4
CVE-2020-16228

In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX4…

Mitigation only
Fix from $1,600 2020-09-11
Patient Information Center Ix MEDIUM 5.0
CVE-2020-16214

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV)…

Mitigation only
Fix from $1,600 2020-09-11
Dreammapper MEDIUM 5.3
CVE-2020-14518

Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.

Fix: after 2.24
Fix from $1,600 2020-08-21
Smartcontrol HIGH 7.3
CVE-2020-7360

An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an a…

Fix: after 4.3.15
Fix from $1,950 2020-08-13
Hue Bridge V2 Firmware HIGH 7.9
CVE-2020-6007

Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during t…

Fix: after 1935144020
Fix from $1,950 2020-01-23
Veradius Unity Firmware MEDIUM 6.5
CVE-2019-18263

An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016…

Mitigation only
Fix from $1,600 2019-12-20
Intellibridge Ec40 Firmware MEDIUM 6.5
CVE-2019-18241

In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the a…

Mitigation only
Fix from $1,600 2019-11-26
Taolight Smart Wi Fi Wiz Connected Led Bulb 9290022656 Firmware HIGH 7.5
CVE-2019-18980

On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation.…

No fix yet
Fix from $1,950 2019-11-14
Tasy Emr MEDIUM 5.3
CVE-2019-13557

In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access …

Fix: after 3.02.1757
Fix from $1,600 2019-11-08
Intellispace Perinatal MEDIUM 6.8
CVE-2019-13546

In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthoriz…

Mitigation only
Fix from $1,600 2019-10-25
Intellivue Mp Monitors Mp20 Mp90 Firmware HIGH 7.2
CVE-2019-13530

Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Ver…

Mitigation only
Fix from $1,950 2019-09-12
Intellivue Mp Monitors Mp20 Mp90 Firmware HIGH 7.2
CVE-2019-13534

Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Ver…

Mitigation only
Fix from $1,950 2019-09-12
Tasy Emr MEDIUM 5.4
CVE-2019-6562

In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in outpu…

Fix: after 3.02.1744
Fix from $1,600 2019-05-01
Intellispace Pacs HIGH 8.8
CVE-2018-17906

Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within …

No fix yet
Fix from $1,950 2018-11-19
E Alert Firmware CRITICAL 9.8
CVE-2018-8856

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption o…

Mitigation only
Fix from $2,300 2018-09-26
E Alert Firmware HIGH 7.5
CVE-2018-8854

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or amount of resources requested …

No fix yet
Fix from $1,950 2018-09-26
E Alert Firmware CRITICAL 9.8
CVE-2018-8850

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to craft the i…

Mitigation only
Fix from $2,300 2018-09-26
E Alert Firmware HIGH 8.8
CVE-2018-8852

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the softw…

Mitigation only
Fix from $1,950 2018-09-26