Philips IntelliSpace Portal and Advanced Visualization Workspace Hardcoded Credentials Vulnerability

Vulnerability

A vulnerability exists in Philips IntelliSpace Portal versions 12 and prior, as well as Advanced Visualization Workspace version 15, due to a lack of protection against reverse engineering. The application binaries are not obfuscated and lack measures to prevent decompilation, disassembly, or debugging. This absence of safeguards allows attackers to reverse-engineer the application, potentially uncovering sensitive information, business logic flaws, and other vulnerabilities. Exploiting this weakness, an attacker identified hardcoded credentials in the 'PortalUsersDatabase.dll', which includes .NET remoting definitions. Within the 'PortalUsersDatabase' namespace, the 'Users' class features 'CreateAdmin' and 'CreateService' functions, designed to initialize accounts in the Portal service. Both functions contain hardcoded encrypted passwords, along with their respective salts, set using the 'SetInitialPasswordAndSalt' function.

Impact

The vulnerability allows for the extraction of hardcoded credentials, which could be used to gain unauthorized access or privileges within the affected applications.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
5.0
exploitability
7.0
remediation
6.0
relevance
0.0
threat
0.0
urgency
1.4
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.