CVE-2020-14525
CVE-2020-14525 is a low-severity vulnerability in Philips Clinical Collaboration Platform with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-83.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- CVSS v2: 2.7
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-83
- Affected product: Philips Clinical Collaboration Platform
- Published:
- Last modified:
Description
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.
Frequently asked questions
- What is CVE-2020-14525?
- Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.
- How severe is CVE-2020-14525?
- CVE-2020-14525 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over an adjacent network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2020-14525 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-14525?
- CVE-2020-14525 affects Philips Clinical Collaboration Platform. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-14525?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2020-14525 published?
- CVE-2020-14525 was published on 2020-09-18 and last updated on 2026-06-17.
References
- https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01
- https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive
Affected products (1)
- cpe:2.3:a:philips:clinical_collaboration_platform:*:*:*:*:*:*:*:*
More vulnerabilities in Philips Clinical Collaboration Platform
- CVE-2020-16247 — Medium (CVSS 6.8): Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere,…
- CVE-2025-27955 — Medium (CVSS 6.5): Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout…
- CVE-2025-27954 — Medium (CVSS 6.5): An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and…
- CVE-2025-27953 — Medium (CVSS 6.5): An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and…
- CVE-2020-16200 — Medium (CVSS 6.5): Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and…
- CVE-2020-16198 — Medium (CVSS 5.0): When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior,…
All CVEs affecting Philips Clinical Collaboration Platform →
Other CWE-83 vulnerabilities
- CVE-2026-45118 — Critical (CVSS 9.3): MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or…
- CVE-2023-32070 — Critical (CVSS 9.0): XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous…
- CVE-2024-26283 — High (CVSS 7.8): An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an…
- CVE-2026-49276 — High (CVSS 7.4): Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any…
- CVE-2025-4615 — High (CVSS 7.2): An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS®…
- CVE-2025-0125 — Medium (CVSS 6.9): An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS®…