CVE-2021-39369

MEDIUM

Philips Vue MyVue PACS through 12.2.x.x - Authenticated Path Traversal via VideoStream Function

Title source: llm
STIX 2.1

Description

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

References (3)

Core 3
Core References
Mitigation, Third Party Advisory, US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01

Scores

CVSS v3 6.5
EPSS 0.0086
EPSS Percentile 54.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (4)
philips/myvue
philips/speech
philips/vue_motion < 12.2.1.5
philips/vue_pacs
Published Dec 26, 2022
Tracked Since Feb 18, 2026