CVE-2019-18263
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
20/12/2019
Last modified:
10/01/2020
Description
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018), Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018). The router software uses an encryption scheme that is not strong enough for the level of protection required.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:philips:veradius_unity_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:philips:veradius_unity:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:philips:pulsera_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:philips:pulsera:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:philips:endura_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:philips:endura:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page