Authentication bypass using an alternate path or channel in Philips products - CVE-2020-14477

 

Authentication bypass using an alternate path or channel in Philips products - CVE-2020-14477

Published: June 26, 2020


Vulnerability identifier: #VU29305
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14477
CWE-ID: CWE-288
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass authentication process.   

The vulnerability exist due to improper implementation of the authentication process. A local user can use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.


Affected software

Ultrasound ClearVue
Ultrasound CX
Ultrasound EPIQ
Ultrasound Affiniti
Ultrasound Sparq
Ultrasound Xperius

How to mitigate CVE-2020-14477

Install updates from vendor's website.

Ultrasound ClearVue - update to 3.3
Ultrasound CX - update to 5.0.3
Ultrasound Sparq - update to 3.0.3

External References

Related Security Bulletins