Vulnerabilities > Philips > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-07-18 CVE-2023-40704 Unspecified vulnerability in Philips VUE Pacs 12.2.8.0
Philips Vue PACS uses default credentials for potentially critical functionality.
network
low complexity
philips
critical
9.8
2017-04-10 CVE-2015-2882 Use of Hard-coded Credentials vulnerability in Philips In.Sight B12037
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.
network
low complexity
philips CWE-798
critical
10.0
2013-10-05 CVE-2013-2808 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Philips products
Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascular Monitoring 5 components, and Xper Information Management servers and workstations for Flex Cardio products before XperConnect 1.5.4.053 SP2 allows remote attackers to execute arbitrary code via a crafted HTTP request to the Connect broker on TCP port 6000.
network
philips CWE-119
critical
9.3