CVE-2025-27954: Command Injection
Published Jun 2, 2025
·Updated
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.
Affected Software
2 affected components
Clinical Collaboration Platform Clinical Collaboration Platform
Philips Clinical Collaboration Platform=12.2.1.5
Event History
Jun 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-27954?
CVE-2025-27954 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2025-27954?
To fix CVE-2025-27954, update to the latest version of the Clinical Collaboration Platform that addresses this vulnerability.
3
What is the impact of CVE-2025-27954?
The impact of CVE-2025-27954 includes exposure of sensitive information and potential to execute arbitrary code by an attacker.
4
Who is affected by CVE-2025-27954?
Users of Clinical Collaboration Platform version 12.2.1.5 are at risk of CVE-2025-27954.
5
Can CVE-2025-27954 be exploited remotely?
Yes, CVE-2025-27954 can be exploited remotely through the usertoken function of default.aspx.