ICSMA-18-340-01
·
Published 2018-12-06
·
View on CISA ICS-CERT ↗
Philips HealthSuite Health Android App
CVSS 3.5
LOW
Risk Summary
Successful exploitation of this vulnerability may allow an attacker with physical access to impact confidentiality and integrity of the product.
CVEs (1)
Remediations
- A new release to mediate this vulnerability with be available during Quarter 1 of 2019.
- As an interim mitigation to this vulnerability, Philips recommends the following:
- Philips advises against jail-breaking or rooting mobile devices. A jail-broken or rooted device means one that is modified outside the mobile device or operating system vendor supported or warranted configurations. Such devices have been freed from the limitations imposed by the mobile service provider and the phone manufacturer. This may affect the performance of the app, weaken the security of the device, and expose users to additional risks.
- Please see the Philips product security website for the latest security information for Philips products:
- https://www.philips.com/productsecurity
Affected Vendors
Philips
Affected Products (1)
Philips
·
Philips HealthSuite Health Android App
vers:all/*
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more