CVE-2021-33020: Philips Vue PACS Use of a Key Past its Expiration Date
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33020?
CVE-2021-33020 refers to a vulnerability in Philips Vue PACS versions 12.2.x.x and prior, where a cryptographic key or password is used past its expiration date, increasing the timing window for cracking attacks.
How does CVE-2021-33020 affect Philips Vue PACS?
CVE-2021-33020 affects Philips Vue PACS versions 12.2.x.x and prior by diminishing its safety significantly and increasing the risk of cracking attacks against the expired cryptographic key or password.
What is the severity of CVE-2021-33020?
CVE-2021-33020 has a severity rating of high with a CVSS score of 7.5.
How can I fix CVE-2021-33020?
To fix CVE-2021-33020, it is recommended to update Philips Vue PACS to a version beyond 12.2.x.x and replace the expired cryptographic key or password with a new one.
Where can I find more information about CVE-2021-33020?
More information about CVE-2021-33020 can be found on the Philips Product Security website and the CISA advisory.