VulnerabilityModified
CVE-2021-39369
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.
MEDIUM 6.5EPSS 0.86%
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.86% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- philips/myvue · philips/speech · philips/vue motion · philips/vue pacs
- Source
- cve@mitre.org
References
- https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01Mitigation, Third Party Advisory, US Government Resource
- https://www.usa.philips.com/healthcareVendor Advisory
- https://www.youtube.com/watch?v=7zC84TNpIxwProduct
- https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01Mitigation, Third Party Advisory, US Government Resource
- https://www.usa.philips.com/healthcareVendor Advisory
- https://www.youtube.com/watch?v=7zC84TNpIxwProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.