CVE-2020-12023 - CVE House
Back to Database
Status published Low CVE-2020-12023

Philips IntelliBridge Enterprise IBE Insertion of Sensitive Information into Log File

Vulnerability Description

Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) are logged within the transaction logs, which are secured behind the login based administrative web portal. The unencrypted user credentials sent from the affected products listed above, for the purpose of handshake or authentication with the Enterprise Systems, are logged as the payload in IntelliBridge Enterprise (IBE) within the transaction logs. An attacker with administrative privileges could exploit this vulnerability to read plain text credentials from log files.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12023

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Customer Indiana University Health reported this vulnerability to Philips.

Affected Vendor

Affected Software

IntelliBridge Enterprise (IBE)
Vulnerable Versions:
0

Timeline

Official Publish: June 11th, 2020
Last Modified: June 4th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)