Skip to main content

Philips Interoperability Solution XDS Vulnerability

A vulnerability in the document sharing system occurs when a LDAP server has a specific configuration.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A vulnerability in the document sharing system occurs when a LDAP server has a specific configuration.


Affected platforms

The following platforms are known to be affected:

Philips Interoperability Solution XDS Versions: 2.5 to 3.11

Philips Interoperability Solution XDS Versions: 2018-1 to 2021-1


Threat details

Philips have announced a vulnerability in the Interoperability Solution XDS product line that occurs when the system is configured to use LDAP via TLS and where the domain controller returns LDAP referrals. This situation could allow an attacker to remotely read LDAP system credentials by gaining access to the network channel used for communication.


Remediation advice

Affected organisations are advised to disable LDAP referrals on their LDAP servers if LDAP via TLS is used and to configure their LDAP servers to include a complete structure to search. Any questions can be directed to Phillips for more information.



Last edited: 25 June 2021 3:31 pm