#VU46651 Input validation error in Patient Information Center iX and PerformanceBridge Focal Point - CVE-2020-16220

 

#VU46651 Input validation error in Patient Information Center iX and PerformanceBridge Focal Point - CVE-2020-16220

Published: September 11, 2020


Vulnerability identifier: #VU46651
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-16220
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Patient Information Center iX
PerformanceBridge Focal Point
Software vendor:
Philips

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of syntactic correctness of input. A remote attacker on the local network can pass specially crafted input to the application and crash the certificate enrollment service.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links