Path Traversal Vulnerability in Philips Vue MyVue PACS
CVE-2021-39369
6.5MEDIUM
Key Information:
- Vendor
Philips
- Vendor
- CVE Published:
- 26 December 2022
What is CVE-2021-39369?
The Philips Vue MyVue PACS, up to version 12.2.x.x, contains a path traversal vulnerability in its VideoStream function. This flaw allows authenticated users to bypass restrictions, enabling them to access files located outside the designated web root. Exploiting this vulnerability may lead to unauthorized exposure of sensitive data, posing significant risks to patient privacy and data integrity.