PT-2020-14798 · Philips · Philips Clinical Collaboration Platform

Published

2020-09-18

·

Updated

2020-09-25

·

CVE-2020-16198

CVSS v3.1

6.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Philips Clinical Collaboration Platform versions 12.2.1 and prior
Description The issue arises when the software fails to properly verify the identity of an attacker, allowing them to claim a given identity without sufficient proof.
Recommendations For versions 12.2.1 and prior, update to a version that contains a fix for this issue, as the current version does not properly validate identity claims. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16198

Affected Products

Philips Clinical Collaboration Platform