CVE-2020-16212
MEDIUMPhilips Patient Information Center IX - Exposure to Wrong Actor
Title source: ruleDescription
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on the surveillance station operates in kiosk mode, which is vulnerable to local breakouts that could allow an attacker with physical access to escape the restricted environment with limited privileges.
Scores
CVSS v3
6.8
EPSS
0.0006
EPSS Percentile
18.3%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-668
Status
published
Affected Products (3)
philips/patient_information_center_ix
philips/patient_information_center_ix
philips/patient_information_center_ix
Timeline
Published
Sep 11, 2020
Tracked Since
Feb 18, 2026