Deserialization Vulnerability in IntelliSpace Portal by Philips
CVE-2025-3425
7.3HIGH
What is CVE-2025-3425?
The IntelliSpace Portal application by Philips is impacted by a deserialization vulnerability stemming from its use of .NET Remoting. This vulnerability is triggered through an unprotected port (755), which allows for potential remote code execution. A critical misconfiguration of the server's TypeFilterLevel, set to Full, exacerbates this security flaw. Therefore, these configurations leave systems vulnerable if not properly mitigated. Affected versions include IntelliSpace Portal 12 and earlier.
Affected Version(s)
IntelliSpace Portal 12 and prior