Skip to main content

Philips Vue PACS Vulnerabilities

Philips have released a series of mitigations for a range of vulnerabilities in Philips Vue PACS products.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Philips have released a series of mitigations for a range of vulnerabilities in Philips Vue PACS products.


Affected platforms

The following platforms are known to be affected:

Philips Vue PACS Versions: 12.2.x.x and prior

Philips Vue MyVue Versions: 12.2.x.x and prior

Philips Vue Speech Versions: 12.2.x.x and prior

Philips Vue Motion: Versions 12.2.1.5 and prior


Threat details

Philips have announced the following vulnerabilities in Philips Vue PACS products. 

  • Cleartext transmission of sensitive information
  • Improper restriction of operations within the bounds of a memory buffer
  • Improper input validation
  • Improper authentication
  • Improper initialisation
  • Use of a broken or risky cryptographic algorithm
  • Protection mechanism failure
  • Use of a key past its expiration date
  • Insecure default initialisation of resource
  • Improper handling of unicode encoding
  • Insufficiently protected credentials
  • Data integrity issues
  • Cross-site scripting
  • Improper neutralisation
  • Use of obsolete function
  • Relative path traversal

An unauthorised person or process could exploit these vulnerabilities to eavesdrop, view or modify data, gain system access, perform code execution, install unauthorised software, or affect system data integrity.


Remediation advice

Affected organisations are advised to read the CISA advisory icsma-21-187-01 and apply the following mitigations recommended by Philips to address these vulnerabilities. Any questions can be directed to Phillips for more information.

Philips has released the following plans to address these vulnerabilities:

  • Philips recommends configuring the Vue PACS environment per D000763414 – Vue_PACS_12_Ports_Protocols_Services_Guide available on Incenter.
  • Philips released Version 12.2.1.5 in June of 2020 for MyVue that remediates CWE-693 and recommends contacting support below.
  • Philips released Version 12.2.1.5 in June of 2020 for Vue Motion that remediates CWE-324 and recommends contacting support below.
  • Philips released Version 12.2.8.0 in May of 2021 for Speech that remediates CWE-693, CWE-319, CWE-119, CWE-287, and CWE-1214 and recommends contacting support below.
  • Philips released Version 12.2.8.0 in May of 2021 for PACS that remediates CWE-20, CWE-119, CWE-287 and recommends contacting support below.
  • Philips released a security fix for Speech in Nov 2021 that remediates CWE-665 and CWE-327 and recommends contacting support below.
  • Philips released version 12.2.1.6 in December 2021 for VuePAC (WFM), Vue Motion (Enterprise Viewer), Vue Explorer, and Web System Configuration that remediates CWE-23. 
  • Philips released Version 12.2.8.100 in Q1 / 2022 for MyVue that remediates CWE-665 and CWE-710  and recommends contacting support below.
  • Philips released Version 12.2.8.100 in Q1 / 2022 for PACS that remediates CWE-79, CWE-693, CWE-665, CWE-1188, CWE-327, CWE-176, CWE-522, CWE-710, and CWE-707 and recommends contacting support below.
  • Philips will release a fix for PACS that remediates CWE-522 with low score of 3.7 in Q3 2023.

Please see the Philips product security website for the latest security information for Philips products.



CVE Vulnerabilities

Last edited: 23 February 2023 4:04 pm