PatchSiren cyber security CVE debrief
CVE-2021-28165 The Eclipse Foundation CVE debrief
CVE-2021-28165 is a denial-of-service vulnerability in Philips Vue PACS versions prior to 12.2.8.410. An attacker with access to the hospital's private network can send numerous requests or large data volumes to exhaust server resources (CPU, memory), causing application crashes or unresponsiveness. The vulnerability does not expose or allow modification of patient data. The attack vector requires adjacent network access with no privileges or user interaction needed. Philips released Vue PACS 12.2.8.410 in October 2023 to address this issue.
- Vendor
- The Eclipse Foundation
- Product
- Vue PACS
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-18
- Original CVE updated
- 2024-11-21
- Advisory published
- 2024-07-18
- Advisory updated
- 2024-11-21
Who should care
Healthcare organizations using Philips Vue PACS for medical imaging, particularly those with versions prior to 12.2.8.410. Hospital IT security teams responsible for medical device network segmentation and availability of critical imaging systems.
Technical summary
The vulnerability exists in Philips Vue PACS versions below 12.2.8.410. Attackers on the adjacent network can trigger CPU and memory exhaustion through high-volume request flooding or large data submissions. The attack requires no authentication or user interaction. Successful exploitation results in application unavailability but does not compromise patient data confidentiality or integrity. The CVSS 3.1 score of 6.5 (Medium) reflects the adjacent network attack vector and high availability impact with no confidentiality or integrity effects.
Defensive priority
medium
Recommended defensive actions
- Upgrade Philips Vue PACS to version 12.2.8.410 or later, released October 2023
- Configure Vue PACS environment per Philips document D000763414 – Vue_PACS_12_Ports_Protocols_Services_Guide available on Incenter
- For managed services customers, contact local Philips sales representative or submit request via Philips Informatics Support portal for release scheduling
- Ensure hospital private network segmentation with firewalls and VPNs to limit attacker access
- Monitor for unusual resource consumption patterns on Vue PACS servers
Evidence notes
Vulnerability details sourced from CISA CSAF advisory ICSMA-24-200-01, published 2024-07-18 and updated 2024-11-21. CVSS 3.1 vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H confirms adjacent network attack vector with high availability impact. Philips remediation guidance specifies version 12.2.8.410 as the fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-28165 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-28165
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-28165 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-28165
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-200-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-200-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.