CVE Database
/

CVE-2020-27298

Back to search

CVE-2020-27298

Published: Jan 20, 2021

Modified: Jun 4, 2025

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.

VendorProductVersions

Philips

Interventional Workspot

affected
Release 1.3.2
affected
Release 1.4.0
affected
Release 1.4.1
affected
Release 1.4.3
affected
Release 1.4.5

Philips

Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live

affected
Release 1.0

Philips

ViewForum

affected
Release 6.3V1L10

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now