Input validation error in PerformanceBridge Focal Point and Patient Information Center iX - CVE-2020-16220

 

Input validation error in PerformanceBridge Focal Point and Patient Information Center iX - CVE-2020-16220

Published: September 11, 2020


Vulnerability identifier: #VU46651
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16220
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of syntactic correctness of input. A remote attacker on the local network can pass specially crafted input to the application and crash the certificate enrollment service.


Affected software

PerformanceBridge Focal Point
Patient Information Center iX

How to mitigate CVE-2020-16220

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins