6.3
CVSSv3

CVE-2018-5438

Published: 20/03/2018 Updated: 20/04/2018
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.3 | Impact Score: 5.2 | Exploitability Score: 1
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker could reuse the session of a previously logged in user. This vulnerability exists when using ISCV together with an Electronic Medical Record (EMR) system, where ISCV is in KIOSK mode for multiple users and using Windows authentication. This may allow an malicious user to gain unauthorized access to patient health information and potentially modify this information.

Vulnerable Product Search on Vulmon Subscribe to Product

philips intellispace cardiovascular