Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-27298


Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.


Published

2021-01-26T18:15:45.990

Last Modified

2025-06-04T20:15:21.807

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application philips coronary_tools 1.0 Yes
Application philips dynamic_coronary_roadmap 1.0 Yes
Application philips interventional_workspot 1.3.2 Yes
Application philips interventional_workspot 1.4.0 Yes
Application philips interventional_workspot 1.4.1 Yes
Application philips interventional_workspot 1.4.3 Yes
Application philips interventional_workspot 1.4.5 Yes
Application philips stentboost_live 1.0 Yes
Application philips viewforum 6.3v1l10 Yes

References