SB2020082404 - Multiple vulnerabilities in Philips SureSigns VS4



SB2020082404 - Multiple vulnerabilities in Philips SureSigns VS4

Published: August 24, 2020

Security Bulletin ID SB2020082404
Severity
Medium
Patch available
NO
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2020-16237)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. An authenticated attacker with physical access can pass specially crafted input to the application and perform a denial of service (DoS) attack.


2) Improper access control (CVE-ID: CVE-2020-16241)

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. An attacker with physical access can bypass implemented security restrictions and gain unauthorized access to the application.


3) Improper Authentication (CVE-ID: CVE-2020-16239)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists when an actor claims to have a given identity due to the software does not prove or insufficiently proves the claim is correct. A remote administrator can bypass authentication process and gain unauthorized access to the application.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.