Philips Interoperability Solution XDS Vulnerability
A vulnerability in the document sharing system occurs when a LDAP server has a specific configuration.
Summary
A vulnerability in the document sharing system occurs when a LDAP server has a specific configuration.
Affected platforms
The following platforms are known to be affected:
Philips Interoperability Solution XDS Versions: 2.5 to 3.11
Philips Interoperability Solution XDS Versions: 2018-1 to 2021-1
Threat details
Philips have announced a vulnerability in the Interoperability Solution XDS product line that occurs when the system is configured to use LDAP via TLS and where the domain controller returns LDAP referrals. This situation could allow an attacker to remotely read LDAP system credentials by gaining access to the network channel used for communication.
Remediation advice
Affected organisations are advised to disable LDAP referrals on their LDAP servers if LDAP via TLS is used and to configure their LDAP servers to include a complete structure to search. Any questions can be directed to Phillips for more information.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 25 June 2021 3:31 pm