CVE-2023-40704

MEDIUM

Philips - Info Disclosure

Title source: llm
STIX 2.1

Description

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.

Scores

CVSS v3 6.8
EPSS 0.0008
EPSS Percentile 23.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1392
Status published
Products (1)
philips/vue_pacs < 12.2.8.410
Published Jul 18, 2024
Tracked Since Feb 18, 2026