Identity Claim Vulnerability in Philips Clinical Collaboration Platform
CVE-2020-16198
6.3MEDIUM
Summary
The Philips Clinical Collaboration Platform, up to version 12.2.1, is susceptible to a vulnerability where an attacker can falsely claim a specific identity within the system. This occurs due to the software's failure to adequately verify the authenticity of the identity claims, potentially allowing unauthorized access to sensitive information and functionality. This vulnerability poses significant risks to data integrity and security within medical environments where the platform is utilized.
Affected Version(s)
Philips Clinical Collaboration Platform Versions 12.2.1 and prior
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved