Vulnerability identifier: #VU14468
Vulnerability risk: Low
CVSSv3.1: 5.3 [CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:W/RC:C]
CVE-ID:
CWE-ID:
CWE-120
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
PageWriter TC70
Hardware solutions /
Firmware
PageWriter TC50
Hardware solutions /
Firmware
PageWriter TC30
Hardware solutions /
Firmware
PageWriter TC20
Hardware solutions /
Firmware
PageWriter TC10
Hardware solutions /
Firmware
Vendor: Philips
Description
The vulnerability allows a local unauthenticated attacker to bypass security restrictions on the target system.
The weakness exists due to boundary error or format string when handling malicious input. A local attacker can supply specially crafted data and trigger memory corruption to access and modify settings on the device.
Mitigation
Philips plans an update to correct these issues in the release scheduled for mid-year 2019.
Philips has also provided the following information regarding an operating system that is no longer supported by the operating system manufacturer:
Philips offers the following additional mitigation advice:
Vulnerable software versions
PageWriter TC70: All versions
PageWriter TC50: All versions
PageWriter TC30: All versions
PageWriter TC20: All versions
PageWriter TC10: All versions
External links
http://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.