CVE-2013-2808
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
05/10/2013
Last modified:
11/04/2025
Description
Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascular Monitoring 5 components, and Xper Information Management servers and workstations for Flex Cardio products before XperConnect 1.5.4.053 SP2 allows remote attackers to execute arbitrary code via a crafted HTTP request to the Connect broker on TCP port 6000.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:philips:xper_information_management_physiomonitoring_5:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:philips:xperconnect:*:*:*:*:*:*:*:* | 1.5.4.053 (including) | |
cpe:2.3:a:philips:xper_information_management_vascular_monitoring_5:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:philips:xperconnect:*:*:*:*:*:*:*:* | 1.5.4.053 (including) | |
cpe:2.3:h:philips:xper_flex_cardio:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:philips:xperconnect:*:*:*:*:*:*:*:* | 1.5.4.053 (including) |
To consult the complete list of CPE names with products and versions, see this page