Vulnerability Details CVE-2018-8852
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2018-8852
-
cpe:2.3:o:philips:e-alert_firmware:-
-
cpe:2.3:o:philips:e-alert_firmware:2.1
-
cpe:2.3:o:philips:e-alert_firmware:r2.1