peter bassill · operator
$ cve CVE-2018-8850 JSON

CVE-2018-8850

9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to craft the input in a form that is not expected by the rest of the application. This would lead to parts of the unit receiving unintended input, which may result in altered control flow, arbitrary control of a resource, or arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.83% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2018-09-26
Last modified2026-06-17

Affected (1)

VendorProduct
philipse-alert firmware

References

→ the Explorer  ·  watch your stack  ·  NVD