Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.
During installation, installed file permissions are set to allow anyone to modify those files.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.usa.philips.com/healthcare/about/customer-support/product-security | vendor advisory |
http://www.securityfocus.com/bid/105194 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01 | mitigation third party advisory us government resource |