CVE-2020-16212

MEDIUM

Philips Patient Information Center IX - Exposure to Wrong Actor

Title source: rule

Description

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on the surveillance station operates in kiosk mode, which is vulnerable to local breakouts that could allow an attacker with physical access to escape the restricted environment with limited privileges.

Scores

CVSS v3 6.8
EPSS 0.0006
EPSS Percentile 18.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-668
Status published

Affected Products (3)

philips/patient_information_center_ix
philips/patient_information_center_ix
philips/patient_information_center_ix

Timeline

Published Sep 11, 2020
Tracked Since Feb 18, 2026