CVE-2013-2808

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/10/2013
Last modified:
11/04/2025

Description

Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascular Monitoring 5 components, and Xper Information Management servers and workstations for Flex Cardio products before XperConnect 1.5.4.053 SP2 allows remote attackers to execute arbitrary code via a crafted HTTP request to the Connect broker on TCP port 6000.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:philips:xper_information_management_physiomonitoring_5:-:*:*:*:*:*:*:*
cpe:2.3:a:philips:xperconnect:*:*:*:*:*:*:*:* 1.5.4.053 (including)
cpe:2.3:a:philips:xper_information_management_vascular_monitoring_5:-:*:*:*:*:*:*:*
cpe:2.3:a:philips:xperconnect:*:*:*:*:*:*:*:* 1.5.4.053 (including)
cpe:2.3:h:philips:xper_flex_cardio:-:*:*:*:*:*:*:*
cpe:2.3:a:philips:xperconnect:*:*:*:*:*:*:*:* 1.5.4.053 (including)