ICSMA-20-261-01: ICSMA-20-261-01_Philips Clinical Collaboration Platform
CISA advisory · released 2020-09-17
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 1, 2020-09-17 (final)
CISA's summary
Summary: Northridge Hospital Medical Center reported these vulnerabilities to Philips.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Philips | Clinical Collaboration Platform | <= 12.2.1 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2020-14506 — CVE-2020-14506 · CWE-668
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.CVE-2020-14506 has been assigned to this vulnerability. A CVSS v3 base score of 3.4 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
- CVE-2020-14525 — CVE-2020-14525 · CWE-668
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.CVE-2020-14525 has been assigned to this vulnerability. A CVSS v3 base score of 3.5 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
- CVE-2020-16198 — CVE-2020-16198 · CWE-668
When an attacker claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.CVE-2020-16198 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).
- CVE-2020-16200 — CVE-2020-16200 · CWE-668
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.CVE-2020-16200 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- CVE-2020-16247 — CVE-2020-16247 · CWE-668
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.CVE-2020-16247 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
Acknowledgments, as the advisory lists them
- Northridge Hospital Medical Center: reporting these vulnerabilities to Philips
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.