CVE-2021-27501
HIGHPhilips Vue PACS <12.2 - Code Injection
Title source: llmDescription
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.
Scores
CVSS v3
7.5
EPSS
0.0022
EPSS Percentile
43.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-710
Status
published
Affected Products (4)
philips/myvue
< 12.2.1.5
philips/speech
< 12.2.8.0
philips/vue_motion
< 12.2.1.5
philips/vue_pacs
< 12.2.8.0
Timeline
Published
Apr 01, 2022
Tracked Since
Feb 18, 2026