Philips MRI 1.5T and 3T Incorrect Ownership Assignment
CVE-2021-26248
5.9MEDIUM
What is CVE-2021-26248?
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Affected Version(s)
MRI 1.5T 5.3 <= 5.8.1
MRI 3T 5.3 <= 5.8.1
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Aguilar, a Secureworks Adversary Group consultant, reported these vulnerabilities to Philips.