PT-2020-12991 · Philips · Earlyvue+3
Published
2020-06-11
·
Updated
2025-06-04
·
CVE-2020-12023
CVSS v3.1
4.5
Medium
| Vector | AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Philips IntelliBridge Enterprise (IBE) versions B.12 and prior
Description
The issue concerns the logging of unencrypted user credentials within the transaction logs of the IntelliBridge Enterprise system. These logs are secured behind a login-based administrative web portal. The credentials are sent from products like SureSigns, EarlyVue, and IntelliVue Guardian for authentication purposes and are logged in plain text. An attacker with administrative privileges could exploit this to read plain text credentials from log files.
Recommendations
For Philips IntelliBridge Enterprise (IBE) versions B.12 and prior, consider restricting access to the transaction logs to minimize the risk of exploitation. As a temporary workaround, limit the administrative privileges to only those necessary for operation, reducing the potential for an attacker to access the logs.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Earlyvue
Intellivue Guardian
Philips Intellibridge Enterprise
Suresigns