Vulnerability Description
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful exploitation could lead to unauthorized access to patient data via a read-only web application.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Philips | Patient Information Center Ix | b.02 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01Third Party AdvisoryUS Government Resource
- https://www.philips.com/productsecurity
- https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01Third Party AdvisoryUS Government Resource
- https://www.philips.com/productsecurity
FAQ
What is CVE-2020-16218?
CVE-2020-16218 is a vulnerability with a CVSS score of 3.5 (LOW). In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then use...
How severe is CVE-2020-16218?
CVE-2020-16218 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16218?
Check the references section above for vendor advisories and patch information. Affected products include: Philips Patient Information Center Ix.