Skip to main content

Philips Gemini PET/CT Family Removable Media Vulnerability

A vulnerability in the Philips Gemini PET/CT Family has been disclosed. A malicious user with physical access could exploit this vulnerability to steal data, including patient information.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A vulnerability in the Philips Gemini PET/CT Family has been disclosed. A malicious user with physical access could exploit this vulnerability to steal data, including patient information.


Affected platforms

The following platforms are known to be affected:

Philips Gemini PET/CT product family

  • 882300 Gemini 16 Slice
  • 882160 Gemini Dual
  • 882400 Gemini GXL 10 Slice
  • 882390 Gemini GXL 6 Slice
  • 882410 Gemini GXL 16 Slice
  • 882412 GEMINI LXL
  • 882473 Gemini TF Ready
  • 882470 Gemini TF 16 w/ TOF Performance
  • 882471 Gemini TF 64 w/ TOF Performance
  • 882476 Gemini TF Big Bore
  • 882438 TruFlight Select PET/CT

Threat details

Introduction

Products in the Philips Gemini PET/CT family store sensitive information on a removable media device that does not have built-in access control. Physical access to the products could allow a malicious user to exploit this vulnerability and acquire the media device and the data stored on it.


Vulnerability details

CVE-2021-27456 - Storage of sensitive data in a mechanism without access control (CWE-921)


Remediation advice

Users and administrators should review the CISA Philips Gemini PET/CT Family advisory for more information. Gemini PET/CT systems should be used according to the recommended specifications. Only authorised personnel should have physical access to the scanner and removable media.



Last edited: 1 April 2021 1:47 pm