Vulnerability identifier: #VU14469
Vulnerability risk: Low
CVSSv3.1: 5.5 [CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:W/RC:C]
CVE-ID:
CWE-ID:
CWE-798
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
PageWriter TC70
Hardware solutions /
Firmware
PageWriter TC50
Hardware solutions /
Firmware
PageWriter TC30
Hardware solutions /
Firmware
PageWriter TC20
Hardware solutions /
Firmware
PageWriter TC10
Hardware solutions /
Firmware
Vendor: Philips
Description
The vulnerability allows a physical attacker with superuser privileges to bypass security restrictions on the target system.
The weakness exists due to use of hardcoded credentials. A physical attacker can enter the superuser password that can be used to access and modify all settings on the device, as well as to reset existing passwords.
Mitigation
Philips plans an update to correct these issues in the release scheduled for mid-year 2019.
Philips has also provided the following information regarding an operating system that is no longer supported by the operating system manufacturer:
Philips offers the following additional mitigation advice:
Vulnerable software versions
PageWriter TC70: All versions
PageWriter TC50: All versions
PageWriter TC30: All versions
PageWriter TC20: All versions
PageWriter TC10: All versions
External links
http://ics-cert.us-cert.gov/advisories/ICSMA-18-228-01
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.