PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-40704 Philips CVE debrief

Philips Vue PACS versions prior to 12.2.8.410 do not enforce unique and complex password creation during installation, allowing continued use of default credentials. An attacker with adjacent network access and high privileges who obtains or guesses the default password could gain database access, with potential impacts to system availability and data integrity. The vulnerability was published on July 18, 2024, and modified on November 21, 2024, when Philips removed other vulnerabilities from the advisory following further analysis showing they did not affect the device or had no security impact. Philips assesses this specific issue as low risk for exploitability and recommends no required action, though customers may request database password updates. Managed services customers may receive new releases subject to resource availability and country-specific regulations.

Vendor
Philips
Product
Vue PACS
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-07-18
Original CVE updated
2024-11-21
Advisory published
2024-07-18
Advisory updated
2024-11-21

Who should care

Healthcare delivery organizations operating Philips Vue PACS installations, particularly those with managed services deployments; biomedical engineering and clinical engineering teams responsible for medical imaging system security; healthcare CISOs and risk management personnel overseeing medical device cybersecurity programs.

Technical summary

The Vue PACS installation process does not mandate unique, complex passwords, permitting continued use of vendor default credentials. Successful exploitation requires adjacent network access and high privileges, with compromise enabling database access that threatens system availability and data integrity.

Defensive priority

medium

Recommended defensive actions

  • Contact your local Philips sales representative or submit a request through the Philips Informatics Support portal to inquire about new release eligibility for managed services installations.
  • Request database password updates from Philips if desired, though no action is required per vendor risk assessment.
  • Review and implement CISA ICS recommended practices for defense-in-depth strategies applicable to medical imaging systems.
  • Monitor the Philips Product Security portal for additional advisory updates.

Evidence notes

Source: CISA CSAF advisory ICSMA-24-200-01. CVSS 3.1 vector: AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Affected product: Philips Vue PACS <12.2.8.410.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-40704 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-40704

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-40704 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-40704

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-200-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.