CVE-2025-27955: Medium severity clinical collaboration platform vulnerability
Published Jun 2, 2025
·Updated
Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.
Affected Software
2 affected components
Clinical Collaboration Platform Clinical Collaboration Platform
Philips Clinical Collaboration Platform=12.2.1.5
Event History
Jun 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-27955?
The severity of CVE-2025-27955 is classified as high due to the potential for remote attackers to exploit a weak logout system.
2
How do I fix CVE-2025-27955?
To mitigate CVE-2025-27955, ensure that the session token is invalidated immediately upon logout.
3
What vulnerabilities are associated with CVE-2025-27955?
CVE-2025-27955 is associated with an inadequate session management mechanism that can lead to unauthorized access.
4
Who is affected by CVE-2025-27955?
Users of Clinical Collaboration Platform version 12.2.1.5 are affected by CVE-2025-27955.
5
What type of attack can exploit CVE-2025-27955?
CVE-2025-27955 can be exploited through session hijacking, allowing remote attackers to execute arbitrary code.