← Back

Philips

philips

115 CVEs • 169 products

Products (169)

Click to collapse
Toggle
Vue Pacs
vue_pacs
Myvue
myvue
Speech
speech
Vue Motion
vue_motion
Xcelera
xcelera
Dosewise
dosewise
Tasy Emr
tasy_emr
Xperconnect
xperconnect
Isite Pacs
isite_pacs
Tasy Webportal
tasy_webportal
Cx50 Firmware
cx50_firmware
Sparq Firmware
sparq_firmware
Smartcontrol
smartcontrol
Dreammapper
dreammapper
Hue Firmware
hue_firmware
Coronary Tools
coronary_tools
Viewforum
viewforum
Engage
engage
Encoreanywhere
encoreanywhere
Alice 6
alice_6

CVEs (115)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Philips
1Clinical Collaboration Platform
Jun 17, 2026
Sep 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data saf...Show more
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.Show less
1Philips
1Patient Information Center Ix
Jun 17, 2026
Sep 11, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length...Show more
In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data, causing the application on the surveillance station to restart.Show less
1Philips
2Patient Information Center Ix
Performancebridge Focal Point
Jun 17, 2026
Sep 11, 2020
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it do...Show more
In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax, causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.Show less
1Philips
13Intellivue Mp2 Mp90 Firmware
Intellivue Mx100 FirmwareIntellivue Mx400 Firmware+10 more
Jun 17, 2026
Sep 11, 2020
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly vali...Show more
In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3 Versions N and prior, the product receives input or data but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly, which can induce a denial-of-service condition through a system restart.Show less
1Philips
1Patient Information Center Ix
Jun 17, 2026
Sep 11, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on th...Show more
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on the surveillance station operates in kiosk mode, which is vulnerable to local breakouts that could allow an attacker with physical access to escape the restricted environment with limited privileges.Show less
1Philips
13Intellivue Mp2 Mp90 Firmware
Intellivue Mx100 FirmwareIntellivue Mx400 Firmware+10 more
Jun 17, 2026
Sep 11, 2020
N/A· v4
6.4 MEDIUM· v3
5.2 MEDIUM· v2
In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions N and prior, the so...Show more
In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX550, MX750, MX850, and IntelliVue X3 Versions N and prior, the software does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a compromised certificate.Show less
1Philips
2Patient Information Center Ix
Performancebridge Focal Point
Jun 17, 2026
Sep 11, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves th...Show more
In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.Show less
1Philips
1Patient Information Center Ix
Jun 17, 2026
Sep 11, 2020
N/A· v4
3.5 LOW· v3
2.7 LOW· v2
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and...Show more
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful exploitation could lead to unauthorized access to patient data via a read-only web application.Show less
1Philips
1Patient Information Center Ix
Jun 17, 2026
Sep 11, 2020
N/A· v4
5.0 MEDIUM· v3
5.8 MEDIUM· v2
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special e...Show more
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.Show less
2Philips
Thomsonstb
2Dtr3502bfta Dvb T2 Firmware
Tht741fta Firmware
Jun 17, 2026
Aug 31, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protoco...Show more
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol.Show less
2Philips
Thomsonstb
2Dtr3502bfta Dvb T2 Firmware
Tht741fta Firmware
Jun 17, 2026
Aug 31, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data deliver...Show more
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.Show less
1Philips
1Suresigns Vs4 Firmware
Jun 17, 2026
Aug 21, 2020
N/A· v4
2.1 LOW· v3
2.1 LOW· v2
Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
1Philips
1Suresigns Vs4 Firmware
Jun 17, 2026
Aug 21, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.
1Philips
1Suresigns Vs4 Firmware
Jun 17, 2026
Aug 21, 2020
N/A· v4
2.1 LOW· v3
2.1 LOW· v2
Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.
1Philips
1Dreammapper
Jun 17, 2026
Aug 21, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.
1Philips
1Smartcontrol
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted...Show more
An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was released after April 15, 2020. (Note, the version numbering system changed significantly between version 4.3.15 and version 1.0.7.)Show less
1Philips
8Affiniti 50 Firmware
Affiniti 70 FirmwareClearvue 350 Firmware+5 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versio...Show more
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.Show less
1Philips
1Intellibridge Enterprise
Jun 17, 2026
Jun 11, 2020
N/A· v4
4.5 MEDIUM· v3
2.7 LOW· v2
Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in t...Show more
Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) are logged within the transaction logs, which are secured behind the login based administrative web portal. The unencrypted user credentials sent from the affected products listed above, for the purpose of handshake or authentication with the Enterprise Systems, are logged as the payload in IntelliBridge Enterprise (IBE) within the transaction logs. An attacker with administrative privileges could exploit this vulnerability to read plain text credentials from log files.Show less
1Philips
1Hue Bridge V2 Firmware
Jun 17, 2026
Jan 23, 2020
N/A· v4
7.9 HIGH· v3
4.3 MEDIUM· v2
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.
1Philips
3Endura Firmware
Pulsera FirmwareVeradius Unity Firmware
Jun 17, 2026
Dec 20, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped b...Show more
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018), Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018). The router software uses an encryption scheme that is not strong enough for the level of protection required.Show less