CVE-2021-27456

LOW

Philips Gemini PET/CT - Info Disclosure

Title source: llm
STIX 2.1

Description

Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsma-21-084-01
Product x_refsource_confirm
https://www.philips.com/productsecurity

Scores

CVSS v3 2.4
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-921 CWE-922
Status published
Products (11)
phillips/gemini_882160_firmware
phillips/gemini_882300_firmware
phillips/gemini_882390_firmware
phillips/gemini_882400_firmware
phillips/gemini_882410_firmware
phillips/gemini_882412_firmware
phillips/gemini_882470_firmware
phillips/gemini_882471_firmware
phillips/gemini_882473_firmware
phillips/gemini_882476_firmware
... and 1 more
Published Mar 23, 2022
Tracked Since Feb 18, 2026