CVE-2021-27501

HIGH

Philips Vue PACS <12.2 - Code Injection

Title source: llm
STIX 2.1

Description

Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-710
Status published
Products (4)
philips/myvue < 12.2.1.5
philips/speech < 12.2.8.0
philips/vue_motion < 12.2.1.5
philips/vue_pacs < 12.2.8.0
Published Apr 01, 2022
Tracked Since Feb 18, 2026