CVE-2019-18241
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
26/11/2019
Last modified:
18/12/2019
Description
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain unauthorized access to the EC40/80 hub.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:philips:intellibridge_ec40_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:philips:intellibridge_ec40:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:philips:intellibridge_ec80_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:philips:intellibridge_ec80:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



