CVE-2020-16241
2.1
Vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Exploitability: 0.7 / Impact: 1.4
Source: NVD
Description
Philips SureSigns VS4, A.07.107 and prior
does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Affected (1)
Products: Philips: Suresigns Vs4 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to a.07.107 |
| Running on/with | Platform Versions |
|---|---|
Philips Suresigns Vs4 | All versions |
Related CWEs
CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (3)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: ics-cert@hq.dhs.gov
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.