PatchSiren cyber security CVE debrief
CVE-2023-40704 Philips CVE debrief
Philips Vue PACS versions prior to 12.2.8.410 do not enforce unique and complex password creation during installation, allowing continued use of default credentials. An attacker with adjacent network access and high privileges who obtains or guesses the default password could gain database access, with potential impacts to system availability and data integrity. The vulnerability was published on July 18, 2024, and modified on November 21, 2024, when Philips removed other vulnerabilities from the advisory following further analysis showing they did not affect the device or had no security impact. Philips assesses this specific issue as low risk for exploitability and recommends no required action, though customers may request database password updates. Managed services customers may receive new releases subject to resource availability and country-specific regulations.
- Vendor
- Philips
- Product
- Vue PACS
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-18
- Original CVE updated
- 2024-11-21
- Advisory published
- 2024-07-18
- Advisory updated
- 2024-11-21
Who should care
Healthcare delivery organizations operating Philips Vue PACS installations, particularly those with managed services deployments; biomedical engineering and clinical engineering teams responsible for medical imaging system security; healthcare CISOs and risk management personnel overseeing medical device cybersecurity programs.
Technical summary
The Vue PACS installation process does not mandate unique, complex passwords, permitting continued use of vendor default credentials. Successful exploitation requires adjacent network access and high privileges, with compromise enabling database access that threatens system availability and data integrity.
Defensive priority
medium
Recommended defensive actions
- Contact your local Philips sales representative or submit a request through the Philips Informatics Support portal to inquire about new release eligibility for managed services installations.
- Request database password updates from Philips if desired, though no action is required per vendor risk assessment.
- Review and implement CISA ICS recommended practices for defense-in-depth strategies applicable to medical imaging systems.
- Monitor the Philips Product Security portal for additional advisory updates.
Evidence notes
Source: CISA CSAF advisory ICSMA-24-200-01. CVSS 3.1 vector: AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Affected product: Philips Vue PACS <12.2.8.410.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-40704 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-40704
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-40704 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-40704
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-200-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.