CVE-2021-27501

HIGH

Philips Vue PACS <12.2 - Code Injection

Title source: llm

Description

Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-710
Status published

Affected Products (4)

philips/myvue < 12.2.1.5
philips/speech < 12.2.8.0
philips/vue_motion < 12.2.1.5
philips/vue_pacs < 12.2.8.0

Timeline

Published Apr 01, 2022
Tracked Since Feb 18, 2026