CVE-2020-14477
Status: ModifiedMedium (4.4)—
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Base score: 4.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.30%
- Percentile among all scored CVEs: 21
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (8)
CWEs
- CWE-288
- CWE-287
References
Raw JSON (NVD)
Show
{
"id": "CVE-2020-14477",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.6,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Philips",
"product": "Ultrasound ClearVue",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "versions 3.2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Philips",
"product": "Ultrasound CX",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "versions 5.0.2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Philips",
"product": "Ultrasound EPIQ/Affiniti",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "versions VM5.0",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Philips",
"product": "Ultrasound Sparq",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "version 3.0.2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Philips",
"product": "Ultrasound Xperius",
"versions": [
{
"status": "affected",
"version": "all versions"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2020-06-26T17:15:10.280",
"references": [
{
"url": "https://www.us-cert.gov/ics/advisories/icsma-20-177-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.us-cert.gov/ics/advisories/icsma-20-177-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-288"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information."
},
{
"lang": "es",
"value": "En Philips Ultrasound ClearVue Versiones 3.2 y anteriores, Ultrasound CX Versiones 5.0.2 y anteriores, Ultrasound EPIQ/Affiniti Versiones VM5.0 y anteriores, Ultrasound Sparq Versiones 3.0.2 y anteriores y Ultrasound Xperius todas las versiones, un atacante puede usar una ruta alternativa o canal que no requiere autenticación del inicio de sesión de servicio alternativo para visualizar o modificar información"
}
],
"lastModified": "2026-06-17T02:54:49.927",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:clearvue_850_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41EF47AE-DEA9-4084-BC3C-75A2972B5EBC",
"versionEndIncluding": "3.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:clearvue_850:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "85C19542-2EF6-490F-8DC9-9AF23DB758B9"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:clearvue_350_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C941F34-8A4B-4F52-B341-374F3BF291D7",
"versionEndIncluding": "3.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:clearvue_350:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C1BB7CF7-FD91-45AF-8C30-32A2DC7BE7D6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:cx50_firmware:5.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F897C7E9-8939-44B7-BDDE-EBDBC7B4AB43"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:cx50:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9E46E77E-C7EB-44A2-823D-FE0E834818AE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:affiniti_70_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2C0626D-174F-4228-8F89-EDE240D4E65B",
"versionEndIncluding": "5.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:affiniti_70:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BB4F2CA8-2D99-445B-B93D-5CD7A727DA9F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:affiniti_50_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22C5C609-110C-46AC-87C2-09599CB1EBFB",
"versionEndIncluding": "5.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:affiniti_50:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CCE8A514-5657-49C4-9C5C-60CA8AE56878"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:epiq_7_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AA21E9F-20B4-457F-84EC-67A591A9EC35",
"versionEndIncluding": "5.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:epiq_7:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F2B0401B-104E-460E-91F6-8F64C0D76C6D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:sparq_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37B54A80-39EA-4EA8-B3EA-467DC8D59E89",
"versionEndIncluding": "3.0.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:sparq:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5D2F8EF5-A57C-4570-A834-EF5A3C1DFA52"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:philips:xperius_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7EC3A16F-8D46-43AB-87EF-6CCD8E344515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:philips:xperius:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "96903833-9A10-4A1A-9AB4-D0B9A3E32035"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}