Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-39369


In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.


Published

2022-12-26T06:15:10.617

Last Modified

2025-04-14T17:15:24.687

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application philips myvue - Yes
Application philips speech - Yes
Application philips vue_motion ≤ 12.2.1.5 Yes
Application philips vue_pacs - Yes

References