CVE-2021-43552: Philips Patient Information Center iX (PIC iX) and Efficia CM Series Use of Hard-coded Cryptographic Key
Published Dec 27, 2021
·Updated
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.
Affected Software
3 affected components
Philips Patient Information Center iX=b.02
Philips Patient Information Center iX=c.02
Philips Patient Information Center iX=c.03
Event History
Dec 27, 2021
CVE Published
via MITRE·06:48 PM
Data Sourced
via MITRE·06:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43552.
2
What is the title of the vulnerability?
The title of the vulnerability is 'The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may...'.
3
Which versions of the Patient Information Center iX (PIC iX) are affected by this vulnerability?
Versions B.02, C.02, and C.03 of the Patient Information Center iX (PIC iX) are affected by this vulnerability.
4
What is the severity of CVE-2021-43552?
The severity of CVE-2021-43552 is medium with a CVSS score of 5.5.
5
How can the vulnerability be fixed?
To fix this vulnerability, it is recommended to update to a version of the Patient Information Center iX (PIC iX) that does not use a hard-coded cryptographic key.