Philips Gemini PET/CT Family Removable Media Vulnerability
A vulnerability in the Philips Gemini PET/CT Family has been disclosed. A malicious user with physical access could exploit this vulnerability to steal data, including patient information.
Summary
A vulnerability in the Philips Gemini PET/CT Family has been disclosed. A malicious user with physical access could exploit this vulnerability to steal data, including patient information.
Affected platforms
The following platforms are known to be affected:
Philips Gemini PET/CT product family
- 882300 Gemini 16 Slice
- 882160 Gemini Dual
- 882400 Gemini GXL 10 Slice
- 882390 Gemini GXL 6 Slice
- 882410 Gemini GXL 16 Slice
- 882412 GEMINI LXL
- 882473 Gemini TF Ready
- 882470 Gemini TF 16 w/ TOF Performance
- 882471 Gemini TF 64 w/ TOF Performance
- 882476 Gemini TF Big Bore
- 882438 TruFlight Select PET/CT
Threat details
Introduction
Products in the Philips Gemini PET/CT family store sensitive information on a removable media device that does not have built-in access control. Physical access to the products could allow a malicious user to exploit this vulnerability and acquire the media device and the data stored on it.
Vulnerability details
CVE-2021-27456 - Storage of sensitive data in a mechanism without access control (CWE-921)
Remediation advice
Users and administrators should review the CISA Philips Gemini PET/CT Family advisory for more information. Gemini PET/CT systems should be used according to the recommended specifications. Only authorised personnel should have physical access to the scanner and removable media.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 1 April 2021 1:47 pm