Vulnerability Description
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Philips | Clearvue 850 Firmware | <= 3.2 |
| Philips | Clearvue 850 | - |
| Philips | Clearvue 350 Firmware | <= 3.2 |
| Philips | Clearvue 350 | - |
| Philips | Cx50 Firmware | 5.0.2 |
| Philips | Cx50 | - |
| Philips | Affiniti 70 Firmware | <= 5.0 |
| Philips | Affiniti 70 | - |
| Philips | Affiniti 50 Firmware | <= 5.0 |
| Philips | Affiniti 50 | - |
| Philips | Epiq 7 Firmware | <= 5.0 |
| Philips | Epiq 7 | - |
| Philips | Sparq Firmware | <= 3.0.2 |
| Philips | Sparq | - |
| Philips | Xperius Firmware | All versions |
| Philips | Xperius | - |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsma-20-177-01Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-20-177-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-14477?
CVE-2020-14477 is a vulnerability with a CVSS score of 3.6 (LOW). In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasoun...
How severe is CVE-2020-14477?
CVE-2020-14477 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14477?
Check the references section above for vendor advisories and patch information. Affected products include: Philips Clearvue 850 Firmware, Philips Clearvue 850, Philips Clearvue 350 Firmware, Philips Clearvue 350, Philips Cx50 Firmware.