CVE-2023-40704

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.
Configurations

Configuration 1 (hide)

cpe:2.3:a:philips:vue_pacs:*:*:*:*:*:*:*:*

History

09 Apr 2025, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 6.8
Summary (en) Philips Vue PACS uses default credentials for potentially critical functionality. (en) The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.

21 Nov 2024, 08:19

Type Values Removed Values Added
References () http://www.philips.com/productsecurity - Product () http://www.philips.com/productsecurity - Product
References () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01 - Third Party Advisory, US Government Resource
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.1

05 Sep 2024, 21:01

Type Values Removed Values Added
References () http://www.philips.com/productsecurity - () http://www.philips.com/productsecurity - Product
References () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01 - () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01 - Third Party Advisory, US Government Resource
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 9.8
First Time Philips
Philips vue Pacs
CPE cpe:2.3:a:philips:vue_pacs:*:*:*:*:*:*:*:*

19 Jul 2024, 13:01

Type Values Removed Values Added
Summary
  • (es) Philips Vue PACS utiliza credenciales predeterminadas para funciones potencialmente críticas.

18 Jul 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-18 17:15

Updated : 2025-04-09 21:16


NVD link : CVE-2023-40704

Mitre link : CVE-2023-40704

CVE.ORG link : CVE-2023-40704


JSON object : View

Products Affected

philips

  • vue_pacs
CWE
CWE-1392

Use of Default Credentials

NVD-CWE-Other