PT-2020-12991 · Philips · Earlyvue+3

Published

2020-06-11

·

Updated

2025-06-04

·

CVE-2020-12023

CVSS v3.1

4.5

Medium

VectorAV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Philips IntelliBridge Enterprise (IBE) versions B.12 and prior
Description The issue concerns the logging of unencrypted user credentials within the transaction logs of the IntelliBridge Enterprise system. These logs are secured behind a login-based administrative web portal. The credentials are sent from products like SureSigns, EarlyVue, and IntelliVue Guardian for authentication purposes and are logged in plain text. An attacker with administrative privileges could exploit this to read plain text credentials from log files.
Recommendations For Philips IntelliBridge Enterprise (IBE) versions B.12 and prior, consider restricting access to the transaction logs to minimize the risk of exploitation. As a temporary workaround, limit the administrative privileges to only those necessary for operation, reducing the potential for an attacker to access the logs.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12023

Affected Products

Earlyvue
Intellivue Guardian
Philips Intellibridge Enterprise
Suresigns