Philips Vue PACS Improper Adherence to Coding Standards
CVE-2021-27501

7.5HIGH

Key Information:

Vendor
Philips
Vendor
CVE Published:
1 April 2022

Summary

Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.

Affected Version(s)

Vue Motion <= 12.2.1.5

Vue MyVue <= 12.2.x.x

Vue PACS <= 12.2.x.x

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philips reported these vulnerabilities to CISA.
.