CVE Published: 26/09/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: icscert |
Vendor: Philips |
Product: e-Alert Unit (non-medical device) Status : PUBLISHED
CVE-2018-8852 Description
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier.