Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18241

Опубликовано: 26 нояб. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 3.3
EPSS Низкий

Описание

In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain unauthorized access to the EC40/80 hub.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:philips:intellibridge_ec40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:philips:intellibridge_ec40:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:philips:intellibridge_ec80_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:philips:intellibridge_ec80:-:*:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.00051
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-326
CWE-326

Связанные уязвимости

github
больше 3 лет назад

In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain unauthorized access to the EC40/80 hub.

EPSS

Процентиль: 16%
0.00051
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-326
CWE-326