CVE-2020-16220
Estado: ModificadaMedia (4.3)—
In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax, causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-1286
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-16220",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.3,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Philips",
"product": "Patient Information Center iX (PICiX)",
"versions": [
{
"status": "affected",
"version": "C.02"
},
{
"status": "affected",
"version": "C.03"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Philips",
"product": "PerformanceBridge Focal Point",
"versions": [
{
"status": "affected",
"version": "A.01"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2020-09-11T14:15:11.503",
"references": [
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.philips.com/productsecurity",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsma-20-254-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.philips.com/productsecurity",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-1286"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Patient Information Center iX (PICiX) Versions C.02, C.03, \nPerformanceBridge Focal Point Version A.01, the product receives input \nthat is expected to be well-formed (i.e., to comply with a certain \nsyntax) but it does not validate or incorrectly validates that the input\n complies with the syntax, causing the certificate enrollment service to\n crash. It does not impact monitoring but prevents new devices from \nenrolling."
},
{
"lang": "es",
"value": "Patient Information Center iX (PICiX) Versiones B.02, C.02, C.03, PerformanceBridge Focal Point Versión A.01, Monitores de paciente IntelliVue MX100, MX400-MX850 y MP2-MP90 Versiones N y anteriores, IntelliVue X3 y X2 Versiones N y anteriores. El producto recibe una entrada que se espera que esté bien formada (es decir, que cumpla con una determinada sintaxis) pero no comprueba o comprueba incorrectamente que la entrada cumple con la sintaxis, causando que el servicio de inscripción de certificados se bloque. No impacta la supervisión, pero evita que se inscriban nuevos dispositivos"
}
],
"lastModified": "2026-06-17T02:57:52.953",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:philips:patient_information_center_ix:b.02:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4FA1FEC-5139-48C1-856C-8062436AE6C6"
},
{
"criteria": "cpe:2.3:a:philips:patient_information_center_ix:c.02:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3220AB2-AC0D-4AC2-90D8-76C02FC693EB"
},
{
"criteria": "cpe:2.3:a:philips:patient_information_center_ix:c.03:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE1FB3E9-E269-434A-B1C2-D54C40F437BE"
},
{
"criteria": "cpe:2.3:a:philips:performancebridge_focal_point:a.01:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3B4CF59B-32DC-4F48-88C5-77B96E937E93"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}