We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-40223

Philips Vue PACS Improper Privilege Management



Assignericscert
Reserved2023-08-21
Published2024-07-18
Updated2024-08-02

Description

Philips Vue PACS does not properly assign, modify, track, or check actor privileges, creating an unintended sphere of control for that actor.



MEDIUM: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
MEDIUM: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

Any version before 12.2.8.410
affected

Credits

TAS Health NZ and Camiel van Es reported these vulnerabilities to Philips. 0x40018dfdc0

References

https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01

http://www.philips.com/productsecurity

cve.org CVE-2023-40223

nvd.nist.gov CVE-2023-40223

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.