CVE Vulnerabilities

CVE-2021-33020

Operation on a Resource after Expiration or Release

Published: Apr 01, 2022 | Modified: Jul 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Weakness

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Affected Software

Name Vendor Start Version End Version
Myvue Philips * 12.2.1.5 (excluding)
Speech Philips * 12.2.8.0 (excluding)
Vue_motion Philips * 12.2.1.5 (excluding)
Vue_pacs Philips * 12.2.8.0 (excluding)

References