When an attacker claims to have a given identity,

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior,
does not prove or insufficiently proves the claim is correct.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-8164 When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficiently proves the claim is correct.
Fixes

Solution

Philips Clinical Collaboration Platform Version 12.2.5 was released in May 2020 to remediate CVE-2020-16198. Users with questions regarding their specific Philips Clinical Collaboration Platform installations and new release eligibility should contact Philips service support, or regional service support https://www.usa.philips.com/healthcare/solutions/customer-service-solutions , or call 1-877-328-2808, option 4. The Philips advisory and the latest security information for Philips products are available at the Philips product security website https://www.philips.com/productsecurity .


Workaround

No workaround given by the vendor.

History

Wed, 04 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
Description Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. When an attacker claims to have a given identity, the software does not prove or insufficiently proves the claim is correct. When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficiently proves the claim is correct.
Title Philips Clinical Collaboration Platform Protection Mechanism Failure
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-06-04T21:17:52.555Z

Reserved: 2020-07-31T00:00:00

Link: CVE-2020-16198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-18T18:15:16.957

Modified: 2025-06-04T22:15:23.507

Link: CVE-2020-16198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.