Identity Claim Vulnerability in Philips Clinical Collaboration Platform
CVE-2020-16198

6.3MEDIUM

Key Information:

Vendor
Philips
Vendor
CVE Published:
18 September 2020

Summary

The Philips Clinical Collaboration Platform, up to version 12.2.1, is susceptible to a vulnerability where an attacker can falsely claim a specific identity within the system. This occurs due to the software's failure to adequately verify the authenticity of the identity claims, potentially allowing unauthorized access to sensitive information and functionality. This vulnerability poses significant risks to data integrity and security within medical environments where the platform is utilized.

Affected Version(s)

Philips Clinical Collaboration Platform Versions 12.2.1 and prior

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.