Philips Intellispace Cardiovascular
cpe:2.3:a:philips:intellispace_cardiovascular:*:*:*:*:*:*:*, +2 more
- <= 4.1
- <= 5.1
An authentication bypass vulnerability has been identified in Philips Intellispace Cardiovascular (ISCV) versions 5.1 and prior. This flaw arises from the Windows login process, where an AuthContext token can be exploited to bypass authentication and replay the session of a logged-in user, potentially granting access to sensitive patient records.
Exploitation of this vulnerability could allow an attacker to bypass authentication and replay the session of a logged-in ISCV user, gaining access to patient records.
Philips Intellispace Cardiovascular users are advised to upgrade to version 5.2 or later. For information on how to initiate this upgrade process, contact a local Philips sales or service representative. Managed services users will receive new releases upon resource availability, subject to country-specific regulations.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.