CVE-2018-8852

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/09/2018
Last modified:
09/10/2019

Description

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:philips:e-alert_firmware:*:*:*:*:*:*:*:* r2.1 (including)