SB2020082404 - Multiple vulnerabilities in Philips SureSigns VS4
Published: August 24, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2020-16237)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. An authenticated attacker with physical access can pass specially crafted input to the application and perform a denial of service (DoS) attack.
2) Improper access control (CVE-ID: CVE-2020-16241)
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. An attacker with physical access can bypass implemented security restrictions and gain unauthorized access to the application.
3) Improper Authentication (CVE-ID: CVE-2020-16239)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists when an actor claims to have a given identity due to the software does not prove or insufficiently proves the claim is correct. A remote administrator can bypass authentication process and gain unauthorized access to the application.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.