CVE-2025-27955: Philips Clinical Collaboration Platform

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.

Affected products

  • Philips Clinical Collaboration Platform: version 12.2.1.5 only

Published 2025-06-02. Last modified 2026-06-17.