Philips Vulnerabilities and Affected Products
Vulnerabilities associated with Vue Motion.
Products
Clear product- e-Alert Unit (non-medical device)9 vulnerabilities
- Philips IntelliSpace Portal9 vulnerabilities
- Hue Bridge8 vulnerabilities
- Vue PACS8 vulnerabilities
- Patient Information Center iX (PICiX)7 vulnerabilities
- Vue Motion7 vulnerabilities
- Vue MyVue7 vulnerabilities
- Vue Speech7 vulnerabilities
- Clinical Collaboration Platform5 vulnerabilities
- Brilliance CT Scanners3 vulnerabilities
- IntelliSpace Portal3 vulnerabilities
- MRI 1.5T3 vulnerabilities
- MRI 3T3 vulnerabilities
- Patient Information Center iX (PIC iX)3 vulnerabilities
- PerformanceBridge Focal Point3 vulnerabilities
- SureSigns VS43 vulnerabilities
- DoseWise Portal2 vulnerabilities
- IntelliBridge EC 40 Hub2 vulnerabilities
- IntelliBridge EC 80 Hub2 vulnerabilities
- Intellispace Cardiovascular (ISCV)2 vulnerabilities
- IntelliSpace Cardiovascular (ISCV) products2 vulnerabilities
- IntelliVue MX40 Patient Worn Monitor2 vulnerabilities
- IntelliVue patient monitors2 vulnerabilities
- PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs2 vulnerabilities
- Philips Alice 6 System2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-33018HIGH | Philips Vue PACS Use of a Broken or Risky Cryptographic AlgorithmThe use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information. CWE-327Apr 1, 2022 | CVSS7.5v3.1 | EPSS0.554% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-33022HIGH | Philips Vue PACS Cleartext Transmission of Sensitive InformationPhilips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. CWE-319Apr 1, 2022 | CVSS7.5v3.1 | EPSS0.634% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-27497MEDIUM | Philips Vue PACS Protection Mechanism FailurePhilips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. CWE-693Apr 1, 2022 | CVSS6.5v3.1 | EPSS0.835% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Philips Vue PACS Insufficiently Protected CredentialsPhilips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval. CWE-522Apr 1, 2022 | CVSS3.7v3.1 | EPSS0.882% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2021-33020HIGH | Philips Vue PACS Use of a Key Past its Expiration DatePhilips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key. | CVSS8.2v3.1 | EPSS0.617% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-27501HIGH | Philips Vue PACS Improper Adherence to Coding StandardsPhilips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities. CWE-710Apr 1, 2022 | CVSS7.5v3.1 | EPSS0.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-27493MEDIUM | Philips Vue PACSPhilips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component. | CVSS6.1v3.1 | EPSS0.669% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |