ID

VAR-202107-1646


CVE

CVE-2021-27493


TITLE

Philips Vue PACS  Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2022-001550

DESCRIPTION

Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component. Philips Vue PACS Is vulnerable to injection.Information may be obtained and information may be tampered with

Trust: 1.71

sources: NVD: CVE-2021-27493 // JVNDB: JVNDB-2022-001550 // VULHUB: VHN-386760

AFFECTED PRODUCTS

vendor:philipsmodel:speechscope:ltversion:12.2.8.0

Trust: 1.0

vendor:philipsmodel:vue pacsscope:ltversion:12.2.8.0

Trust: 1.0

vendor:philipsmodel:vue motionscope:ltversion:12.2.1.5

Trust: 1.0

vendor:philipsmodel:myvuescope:ltversion:12.2.1.5

Trust: 1.0

vendor:フィリップスmodel:vue speechscope: - version: -

Trust: 0.8

vendor:フィリップスmodel:vue pacsscope: - version: -

Trust: 0.8

vendor:フィリップスmodel:vue motionscope: - version: -

Trust: 0.8

vendor:フィリップスmodel:vue myvuescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-001550 // NVD: CVE-2021-27493

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-27493
value: MEDIUM

Trust: 1.0

ics-cert@hq.dhs.gov: CVE-2021-27493
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-27493
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202107-245
value: MEDIUM

Trust: 0.6

VULHUB: VHN-386760
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-27493
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-386760
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-27493
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.5
version: 3.1

Trust: 1.0

ics-cert@hq.dhs.gov: CVE-2021-27493
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.1

Trust: 1.0

NVD: CVE-2021-27493
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-386760 // JVNDB: JVNDB-2022-001550 // CNNVD: CNNVD-202107-245 // NVD: CVE-2021-27493 // NVD: CVE-2021-27493

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:injection (CWE-74) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-001550 // NVD: CVE-2021-27493

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202107-245

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202107-245

PATCH

title:Philips Product Security Designed-Inurl:https://www.usa.philips.com/healthcare/about/customer-support/product-security

Trust: 0.8

title:Philips Vue PACS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=179174

Trust: 0.6

sources: JVNDB: JVNDB-2022-001550 // CNNVD: CNNVD-202107-245

EXTERNAL IDS

db:NVDid:CVE-2021-27493

Trust: 3.3

db:ICS CERTid:ICSMA-21-187-01

Trust: 2.5

db:JVNid:JVNVU96012689

Trust: 0.8

db:JVNDBid:JVNDB-2022-001550

Trust: 0.8

db:CNNVDid:CNNVD-202107-245

Trust: 0.6

db:VULHUBid:VHN-386760

Trust: 0.1

sources: VULHUB: VHN-386760 // JVNDB: JVNDB-2022-001550 // CNNVD: CNNVD-202107-245 // NVD: CVE-2021-27493

REFERENCES

url:https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01

Trust: 2.5

url:http://www.philips.com/productsecurity

Trust: 1.7

url:https://jvn.jp/vu/jvnvu96012689/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-27493

Trust: 0.8

url:https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2021-27493/

Trust: 0.6

sources: VULHUB: VHN-386760 // JVNDB: JVNDB-2022-001550 // CNNVD: CNNVD-202107-245 // NVD: CVE-2021-27493

CREDITS

Antonio Kulhanek reported CVE-2021-39369 to Philips. Philips reported these vulnerabilities to CISA.

Trust: 0.6

sources: CNNVD: CNNVD-202107-245

SOURCES

db:VULHUBid:VHN-386760
db:JVNDBid:JVNDB-2022-001550
db:CNNVDid:CNNVD-202107-245
db:NVDid:CVE-2021-27493

LAST UPDATE DATE

2024-08-14T13:07:59.149000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-386760date:2022-07-12T00:00:00
db:JVNDBid:JVNDB-2022-001550date:2022-04-18T07:32:00
db:CNNVDid:CNNVD-202107-245date:2022-07-14T00:00:00
db:NVDid:CVE-2021-27493date:2022-07-12T17:42:04.277

SOURCES RELEASE DATE

db:VULHUBid:VHN-386760date:2022-04-01T00:00:00
db:JVNDBid:JVNDB-2022-001550date:2022-04-18T00:00:00
db:CNNVDid:CNNVD-202107-245date:2021-07-06T00:00:00
db:NVDid:CVE-2021-27493date:2022-04-01T23:15:09.207