First published: Fri Jan 07 2022(Updated: )
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Engage | <6.2.2 |
Philips released and deployed updated Version 6.2.2 in September of 2021, which mitigated this vulnerability. Engage is a hosted application and users don’t need to take any action.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23173 is a vulnerability in the Philips Engage product that allows an authenticated user to gain unauthorized access to sensitive data.
CVE-2021-23173 has a severity rating of 4.3, which is considered medium.
The affected software for CVE-2021-23173 is Philips Engage version up to and excluding 6.2.2.
An authenticated user can exploit CVE-2021-23173 by bypassing access controls and gaining unauthorized access to sensitive data.
To mitigate CVE-2021-23173, update your Philips Engage software to version 6.2.2 or later, as this vulnerability is fixed in that version.