CVE-2020-16220 is a vulnerability affecting Philips Patient Information Center iX (PICiX) Versions C.02, C.03, and PerformanceBridge Focal Point Version A.01. This flaw stems from improper input validation, causing the certificate enrollment service to crash, which prevents new devices from enrolling, though it does not impact existing monitoring. The vulnerability has a CVSS v3.1 score of 4.3 (Medium), indicating a low-impact availability issue (A:L) that can be exploited via adjacent network access (AV:A) with low attack complexity (AC:L) and no user interaction (UI:N). While it disrupts new device enrollment, it does not compromise confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, with only one mention and one article, suggesting low overall attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
b.02CPE matchmatch criteria | cpe:2.3:a:philips:patient_information_center_ix:b.02:*:*:*:*:*:*:* | ||
c.02CPE matchmatch criteria | cpe:2.3:a:philips:patient_information_center_ix:c.02:*:*:*:*:*:*:* | ||
c.03CPE matchmatch criteria | cpe:2.3:a:philips:patient_information_center_ix:c.03:*:*:*:*:*:*:* | ||
a.01CPE matchmatch criteria | cpe:2.3:a:philips:performancebridge_focal_point:a.01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.