CVE-2017-9656 describes a critical vulnerability in Philips DoseWise Portal versions 1.1.7.333 and 2.1.1.3069, where hard-coded database credentials with high privileges are present in backend system files. An attacker with elevated privileges to access these files could exploit this to compromise the confidentiality, integrity, and availability of the database, which contains Protected Health Information (PHI). With a CVSS v3 score of 9.1 (CRITICAL), the vulnerability has a network attack vector and low attack complexity, but requires high privileges for initial access. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.7.333CPE matchmatch criteria | cpe:2.3:a:philips:dosewise:1.1.7.333:*:*:*:*:*:*:* | ||
2.1.1.3069CPE matchmatch criteria | cpe:2.3:a:philips:dosewise:2.1.1.3069:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.