CVE-2020-14518

Philips DreamMapper Insertion of Sensitive Information into Log File

Description

Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.

Remediation

Solution:

  • Philips plans a new release for the DreamMapper app by June 30, 2021, that remediates this vulnerability. Users with questions regarding their specific Philips DreamMapper installations should contact a Philips service support team or regional service support https://www.usa.philips.com/healthcare/solutions/customer-service-solutions . The Philips advisory is available at the following URL: http://www.philips.com/productsecurity Please see the Philips product security website https://www.philips.com/productsecurity for the latest security information for Philips products.

Category

5.3
CVSS
Severity: Medium
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.18%
Third-Party Advisory cisa.gov
Affected: Philips DreamMapper
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2020-14518?
CVE-2020-14518 has been scored as a medium severity vulnerability.
How to fix CVE-2020-14518?
To fix CVE-2020-14518: Philips plans a new release for the DreamMapper app by June 30, 2021, that remediates this vulnerability. Users with questions regarding their specific Philips DreamMapper installations should contact a Philips service support team or regional service support https://www.usa.philips.com/healthcare/solutions/customer-service-solutions . The Philips advisory is available at the following URL: http://www.philips.com/productsecurity Please see the Philips product security website https://www.philips.com/productsecurity for the latest security information for Philips products.
Is CVE-2020-14518 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2020-14518 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2020-14518?
CVE-2020-14518 affects Philips DreamMapper.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.