CVE-2021-27493

Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
References
Link Resource
http://www.philips.com/productsecurity Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:philips:myvue:*:*:*:*:*:*:*:*
cpe:2.3:a:philips:speech:*:*:*:*:*:*:*:*
cpe:2.3:a:philips:vue_motion:*:*:*:*:*:*:*:*
cpe:2.3:a:philips:vue_pacs:*:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-74 NVD-CWE-Other

08 Apr 2022, 18:56

Type Values Removed Values Added
References (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01 - (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01 - Third Party Advisory, US Government Resource
References (CONFIRM) http://www.philips.com/productsecurity - (CONFIRM) http://www.philips.com/productsecurity - Vendor Advisory
CWE CWE-74
CVSS v2 : unknown
v3 : unknown
v2 : 6.4
v3 : 6.5
CPE cpe:2.3:a:philips:speech:*:*:*:*:*:*:*:*
cpe:2.3:a:philips:myvue:*:*:*:*:*:*:*:*
cpe:2.3:a:philips:vue_pacs:*:*:*:*:*:*:*:*
cpe:2.3:a:philips:vue_motion:*:*:*:*:*:*:*:*
First Time Philips
Philips vue Pacs
Philips myvue
Philips speech
Philips vue Motion

01 Apr 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-01 23:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-27493

Mitre link : CVE-2021-27493

CVE.ORG link : CVE-2021-27493


JSON object : View

Products Affected

philips

  • speech
  • vue_pacs
  • myvue
  • vue_motion