4.4

CVE-2020-14477

In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.

Data is provided by the National Vulnerability Database (NVD)
PhilipsClearvue 850 Firmware Version <= 3.2
   PhilipsClearvue 850 Version-
PhilipsClearvue 350 Firmware Version <= 3.2
   PhilipsClearvue 350 Version-
PhilipsCx50 Firmware Version5.0.2
   PhilipsCx50 Version-
PhilipsAffiniti 70 Firmware Version <= 5.0
   PhilipsAffiniti 70 Version-
PhilipsAffiniti 50 Firmware Version <= 5.0
   PhilipsAffiniti 50 Version-
PhilipsEpiq 7 Firmware Version <= 5.0
   PhilipsEpiq 7 Version-
PhilipsSparq Firmware Version <= 3.0.2
   PhilipsSparq Version-
PhilipsXperius Firmware
   PhilipsXperius Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.112
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvd@nist.gov 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
ics-cert@hq.dhs.gov 3.6 1 2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.