Authentication bypass using an alternate path or channel in Philips products - CVE-2020-14477
Published: June 26, 2020
Vulnerability identifier: #VU29305
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14477
CWE-ID: CWE-288
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass authentication process.
The vulnerability exist due to improper implementation of the authentication process. A local user can use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.
Affected software
Ultrasound ClearVue
Ultrasound CX
Ultrasound EPIQ
Ultrasound Affiniti
Ultrasound Sparq
Ultrasound Xperius
Ultrasound CX
Ultrasound EPIQ
Ultrasound Affiniti
Ultrasound Sparq
Ultrasound Xperius
How to mitigate CVE-2020-14477
Install updates from vendor's website.
Ultrasound ClearVue - update to 3.3
Ultrasound CX - update to 5.0.3
Ultrasound Sparq - update to 3.0.3
Ultrasound CX - update to 5.0.3
Ultrasound Sparq - update to 3.0.3