Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Philips

First CVE: Oct 5, 2013Active for: 13 yearsTotal CVEs: 115
54.6
VTI Score
TOP TARGET

Philips maintains a moderately broad portfolio spanning healthcare information systems, clinical platforms, and consumer smart-home devices, creating a diverse attack surface that ranges from hospital networks to consumer endpoints. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure does not show a meaningful pattern toward public exploit availability or confirmed in-the-wild exploitation. The recurring weaknesses cluster around hard-coded credentials, heap-based buffer overflows, and improper input validation, reflecting both the embedded-firmware demands of networked medical and consumer devices and the authentication and parsing challenges common to interconnected healthcare platforms. Defenders should prioritize Philips healthcare products deployed in clinical environments and inventory consumer smart-home infrastructure for credential exposure and memory-safety risks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
115
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
1.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Philips over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2013
12 years ago
Most Recent CVE
Mar 16, 2026
130 days ago

Self-Reporting Analysis

Of all the CVEs published by Philips as a CNA, 50.0% affect products that Philips develops as a vendor.

50.0%
50.0%
Self-reported: 3 (50.0%)
Third-party: 3 (50.0%)

Of all the CVEs published that affect products developed by Philips, 2.6% are self-published by Philips as a CNA.

97.4%
Self-published: 3 (2.6%)
Other CNAs: 112 (97.4%)

Products(169 total)

Top CVEs

Signals from CVEs in this vendor scope (115 CVEs).

115 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-0199HIGH
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows
Apr 12, 20177.898YESYES
CVE-2017-0143HIGH
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gol
Mar 17, 20178.898YESYES
CVE-2018-5472CRITICAL
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unauthorized access and in some cas
Mar 26, 20189.833NONO
CVE-2018-5451CRITICAL
In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. Th
Mar 28, 20189.832NONO
CVE-2021-27497CRITICAL
Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Apr 1, 20229.831NONO
CVE-2018-8856CRITICAL
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data.
Sep 26, 20189.831NONO
CVE-2018-5474CRITICAL
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execute arbitrary code or cause the applicatio
Mar 26, 20189.831NONO
CVE-2026-3560HIGH
Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute a
Mar 13, 20268.830NONO
CVE-2026-3556HIGH
Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code
Mar 13, 20268.830NONO
CVE-2021-27501CRITICAL
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated
Apr 1, 20229.830NONO
View all 115 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products115 CVEs
38%
46%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local20 (17.4%)
Network52 (45.2%)
Unknown1 (0.9%)
Physical7 (6.1%)
Adjacent Network35 (30.4%)
Attack Complexity
Low106 (92.2%)
High8 (7.0%)
Unknown1 (0.9%)
User Interaction
None103 (89.6%)
Unknown1 (0.9%)
Required11 (9.6%)
Privileges Required
Low29 (25.2%)
High12 (10.4%)
None73 (63.5%)
Unknown1 (0.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (115 CVEs).

CISA KEV
2 CVEs
1.7% of CVEs· 99th percentile
Metasploit
2 CVEs
1.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Philips.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Philips — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Philips's Products

View all 8 CNAs →

Top CWEs