Philips Vue PACS Improper Adherence to Coding Standards
CVE-2021-27501
7.5HIGH
Key Information:
- Vendor
- Philips
- Vendor
- CVE Published:
- 1 April 2022
Summary
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.
Affected Version(s)
Vue Motion <= 12.2.1.5
Vue MyVue <= 12.2.x.x
Vue PACS <= 12.2.x.x
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philips reported these vulnerabilities to CISA.