#VU46829 Algorithm Downgrade in Clinical Collaboration Platform


Published: 2020-09-18 | Updated: 2020-09-21

Vulnerability identifier: #VU46829

Vulnerability risk: Low

CVSSv3.1: 6 [CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2020-16200

CWE-ID: CWE-757

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
Clinical Collaboration Platform
Hardware solutions / Medical equipment

Vendor: Philips

Description

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to the affected software does not properly control the allocation and maintenance of a limited resource. A remote attacker on the local network can influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

Clinical Collaboration Platform: 12.2.1


External links
http://us-cert.cisa.gov/ics/advisories/icsma-20-261-01


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability