CVE Feed

    Dashboard / CVE / CVE-2020-27298

    CVE-2020-27298

    Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.

    Published:Jan 20, 2021
    Last Modified:Jun 4, 2025
    EPS:Jan 20, 2021
    EPSS Score:0.00294
    CVSS Score:6.5

    Affected Products

    Vendor
    Philips
    Product
    Coronary Tools
    Vendor
    Philips
    Product
    Dynamic Coronary Roadmap
    Vendor
    Philips
    Product
    Interventional Workspot
    Vendor
    Philips
    Product
    Stentboost Live
    Vendor
    Philips
    Product
    Viewforum

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High