CVE-2021-33024: Philips Vue PACS Insufficiently Protected Credentials
Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33024?
CVE-2021-33024 is a vulnerability in Philips Vue PACS versions 12.2.x.x and prior that allows for unauthorized interception or retrieval of authentication credentials.
What is the severity of CVE-2021-33024?
CVE-2021-33024 has a severity level of high, with a CVSS score of 7.5.
Which software versions are affected by CVE-2021-33024?
Philips Vue PACS versions 12.2.x.x and prior, Philips Myvue, Philips Speech, and Philips Vue Motion are affected by CVE-2021-33024.
How can an attacker exploit CVE-2021-33024?
An attacker can exploit CVE-2021-33024 by intercepting or retrieving authentication credentials stored or transmitted by vulnerable versions of Philips Vue PACS.
Are there any references for CVE-2021-33024?
Yes, you can find more information about CVE-2021-33024 on the Philips product security page and the US-CERT ICS Advisory page.