First published: Thu Nov 18 2021(Updated: )
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Patient Information Center Ix | =b.02 | |
Philips Patient Information Center Ix | =c.02 | |
Philips Patient Information Center Ix | =c.03 | |
=b.02 | ||
=c.02 | ||
=c.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-43552.
The title of the vulnerability is 'The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may...'.
Versions B.02, C.02, and C.03 of the Patient Information Center iX (PIC iX) are affected by this vulnerability.
The severity of CVE-2021-43552 is medium with a CVSS score of 5.5.
To fix this vulnerability, it is recommended to update to a version of the Patient Information Center iX (PIC iX) that does not use a hard-coded cryptographic key.