Vulnerabilities > Philips > Intellispace Cardiovascular > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-08-22 CVE-2018-14789 Unquoted Search Path or Element vulnerability in Philips Intellispace Cardiovascular and Xcelera
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary code and escalate their level of privileges.
local
low complexity
philips CWE-428
6.7
2018-03-20 CVE-2018-5438 Insufficient Session Expiration vulnerability in Philips Intellispace Cardiovascular 2.3.0
Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker could reuse the session of a previously logged in user.
local
high complexity
philips CWE-613
6.3