Significant Vulnerabilities Identified in Philips Vue PACS Medical Imaging Systems
Date: July 9, 2021
A series of security vulnerabilities have been revealed in the Philips Clinical Collaboration Platform Portal (commonly known as Vue PACS). Some of these vulnerabilities could potentially be exploited by malicious actors to gain control over affected systems. According to a warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), “Successful exploitation of these vulnerabilities could allow an unauthorized person or process to eavesdrop, view or modify data, gain system access, perform code execution, install unauthorized software, or compromise system data integrity, thereby threatening the confidentiality, integrity, or availability of the system.”
These 15 vulnerabilities affect the following systems:
- VUE Picture Archiving and Communication Systems (versions 12.2.x.x and earlier)
- Vue MyVue (versions 12.2.x.x and earlier)
- Vue Speech (versions 12.2.x.x and earlier)
- Vue Motion (versions 12.2.1.5 and earlier)
Notably, four specific issues (CVE-2020-1938, CVE-2018-12326, CVE-2018-11218, CVE-2020-4670, and CVE-2018-8014) have been assigned a Critical rating.
Critical Security Vulnerabilities Identified in Philips Vue PACS Imaging Systems On July 9, 2021, significant security vulnerabilities were reported in the Philips Clinical Collaboration Platform Portal, commonly referred to as Vue PACS. These vulnerabilities pose a serious risk, as they…