CVE-2021-33020
01.04.2022, 23:15
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.Enginsight
Vendor | Product | Version |
---|---|---|
philips | myvue | 𝑥 < 12.2.1.5 |
philips | speech | 𝑥 < 12.2.8.0 |
philips | vue_motion | 𝑥 < 12.2.1.5 |
philips | vue_pacs | 𝑥 < 12.2.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-324 - Use of a Key Past its Expiration DateThe product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
- CWE-672 - Operation on a Resource after Expiration or ReleaseThe software uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.