Lucene search

K
cvelistIcscertCVELIST:CVE-2020-16214
HistorySep 11, 2020 - 12:53 p.m.

CVE-2020-16214 Philips Patient Monitoring Devices Improper Neutralization of Formula Elements in a CSV File

2020-09-1112:53:15
CWE-1236
icscert
www.cve.org

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.8%

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the
software saves user-provided information into a comma-separated value
(CSV) file, but it does not neutralize or incorrectly neutralizes
special elements that could be interpreted as a command when the file is
opened by spreadsheet software.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Patient Information Center iX (PICiX)",
    "vendor": "Philips ",
    "versions": [
      {
        "status": "affected",
        "version": "B.02"
      },
      {
        "status": "affected",
        "version": "C.02"
      },
      {
        "status": "affected",
        "version": "C.03"
      }
    ]
  }
]

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.8%

Related for CVELIST:CVE-2020-16214