← Back to home
ICSMA-24-200-01  ·  Published 2024-11-21  ·  View on CISA ICS-CERT ↗

Philips Vue PACS (Update A)

CVSS 6.8 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain access to the database, which could impact system availability and data integrity or cause a denial-of-service condition.

Remediations

  • Philips recommends the following mitigations:
  • For CVE-2021-28165, Philips recommends configuring the Vue PACS environment per D000763414 – Vue_PACS_12_Ports_Protocols_Services_Guide available on Incenter. Vue PACS version 12.2.8.410* released in October 2023 prevents this vulnerability.
  • For managed services customers, new releases will be made available upon resource availability. Releases are subject to country specific regulations. Users with questions regarding their specific Philips Vue PACS installations and new release eligibility should contact their local Philips sales representative or submit a request in the Philips Informatics Support portal.
  • Refer to the Philips advisory for more details.
  • For CVE-2023-40704, Philips recommends no action needed due to low risk of exploitability, but customers can request that Philips update database password(s).

Affected Vendors

Philips

Affected Products (1)

Philips · Vue PACS <12.2.8.410

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more