CVE-2020-27298
Summary
| CVE | CVE-2020-27298 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-26 18:15:00 UTC |
| Updated | 2021-02-02 19:03:00 UTC |
| Description | Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Philips | Coronary Tools | 1.0 | All | All | All |
| Application | Philips | Coronary Tools | 1.0 | All | All | All |
| Application | Philips | Dynamic Coronary Roadmap | 1.0 | All | All | All |
| Application | Philips | Dynamic Coronary Roadmap | 1.0 | All | All | All |
| Application | Philips | Interventional Workspot | 1.3.2 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.0 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.1 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.3 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.5 | All | All | All |
| Application | Philips | Interventional Workspot | 1.3.2 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.0 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.1 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.3 | All | All | All |
| Application | Philips | Interventional Workspot | 1.4.5 | All | All | All |
| Application | Philips | Stentboost Live | 1.0 | All | All | All |
| Application | Philips | Stentboost Live | 1.0 | All | All | All |
| Application | Philips | Viewforum | 6.3v1l10 | All | All | All |
| Application | Philips | Viewforum | 6.3v1l10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Philips Interventional Workstations | CISA | MISC | us-cert.cisa.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.