CVE-2019-18241 Information
Feb 14, 2021
cve
Description
In Philips IntelliBridge EC40 and EC80 IntelliBridge EC40 Hub all versions and IntelliBridge EC80 Hub all versions the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain unauthorized access to the EC40/80 hub.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://www.us-cert.gov/ics/advisories/icsma-19-318-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: