CVE Vulnerabilities

CVE-2023-40704

Use of Default Credentials

Published: Jul 18, 2024 | Modified: Apr 09, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The product does not require unique and complex passwords to be created during installation. Using Philipss default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.

Weakness 

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Affected Software 

Name Vendor Start Version End Version
Vue_pacs Philips * 12.2.8.410 (excluding)

Potential Mitigations 

References