4.4

CVE-2020-14477

Philips Ultrasound Systems Authentication Bypass Using an Alternate Path or Channel

In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Philips ≫ Clearvue 850 Firmware Version <= 3.2
   Philips ≫ Clearvue 850 Version -
Philips ≫ Clearvue 350 Firmware Version <= 3.2
   Philips ≫ Clearvue 350 Version -
Philips ≫ Cx50 Firmware Version 5.0.2
   Philips ≫ Cx50 Version -
Philips ≫ Affiniti 70 Firmware Version <= 5.0
   Philips ≫ Affiniti 70 Version -
Philips ≫ Affiniti 50 Firmware Version <= 5.0
   Philips ≫ Affiniti 50 Version -
Philips ≫ Epiq 7 Firmware Version <= 5.0
   Philips ≫ Epiq 7 Version -
Philips ≫ Sparq Firmware Version <= 3.0.2
   Philips ≫ Sparq Version -
Philips ≫ Xperius Firmware
   Philips ≫ Xperius Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.205
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
DHS.gov 3.6 1 2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

https://www.us-cert.gov/ics/advisories/icsma-20-177-01
Third Party Advisory
US Government Resource