Vulnerability Description
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on the surveillance station operates in kiosk mode, which is vulnerable to local breakouts that could allow an attacker with physical access to escape the restricted environment with limited privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Philips | Patient Information Center Ix | b.02 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01Third Party AdvisoryUS Government Resource
- https://www.philips.com/productsecurity
- https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01Third Party AdvisoryUS Government Resource
- https://www.philips.com/productsecurity
FAQ
What is CVE-2020-16212?
CVE-2020-16212 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. T...
How severe is CVE-2020-16212?
CVE-2020-16212 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16212?
Check the references section above for vendor advisories and patch information. Affected products include: Philips Patient Information Center Ix.