CVE-2020-14477
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.5
Source: NVD
Description
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2 |
| Running on/with | Platform Versions |
|---|---|
Philips Clearvue 850 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2 |
| Running on/with | Platform Versions |
|---|---|
Philips Clearvue 350 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0.2 |
| Running on/with | Platform Versions |
|---|---|
Philips Cx50 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Philips Affiniti 70 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Philips Affiniti 50 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Philips Epiq 7 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Philips Sparq | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Philips Xperius | All versions |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-288
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.