E Alert Firmware
Vendor:
First CVE: Sep 26, 2018 · Active for 7 years
10
Total CVEs
More Total CVEs than 89% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact E Alert Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2018
7 years ago
Most Recent CVE
Apr 1, 2022
1,578 days ago
CVE Severity & Scoring
E Alert Firmware10 CVEs
30%
50%
20%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (20.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8856CRITICAL Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data. | Sep 26, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-8850CRITICAL Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to craft the input in a form that is not expe | Sep 26, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-8844HIGH Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was | Sep 26, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-8852HIGH Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the oppor | Sep 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-8842HIGH Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sn | Sep 26, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-8854HIGH Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or amount of resources requested or influenced by an actor, whic | Sep 26, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-8848HIGH Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor. | Sep 26, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-8846MEDIUM Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output | Sep 26, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-14803MEDIUM Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that could allow attackers to obtain extraneous pr | Sep 26, 2018 | 5.3 | 18 | NO | NO |
CVE-2022-0922MEDIUM The software does not perform any authentication for critical system functionality. | Apr 1, 2022 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For E Alert Firmware
Top CWEs
Versions
No cataloged versions.