LOW · 3.6

CVE-2020-14477

In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasoun...

Vulnerability Description

In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.

CVSS Score

3.6

LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
PhilipsClearvue 850 Firmware<= 3.2
PhilipsClearvue 850-
PhilipsClearvue 350 Firmware<= 3.2
PhilipsClearvue 350-
PhilipsCx50 Firmware5.0.2
PhilipsCx50-
PhilipsAffiniti 70 Firmware<= 5.0
PhilipsAffiniti 70-
PhilipsAffiniti 50 Firmware<= 5.0
PhilipsAffiniti 50-
PhilipsEpiq 7 Firmware<= 5.0
PhilipsEpiq 7-
PhilipsSparq Firmware<= 3.0.2
PhilipsSparq-
PhilipsXperius FirmwareAll versions
PhilipsXperius-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-14477?

CVE-2020-14477 is a vulnerability with a CVSS score of 3.6 (LOW). In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasoun...

How severe is CVE-2020-14477?

CVE-2020-14477 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-14477?

Check the references section above for vendor advisories and patch information. Affected products include: Philips Clearvue 850 Firmware, Philips Clearvue 850, Philips Clearvue 350 Firmware, Philips Clearvue 350, Philips Cx50 Firmware.