← Back

CVE-2021-39369

nvd nist
Published: Dec 26, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

Affected (4)

4 products
Myvue
Speech
Vue Motion
Vue Pacs
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Up to 12.2.1.5
All versions

References (6)

Source: cve@mitre.org
MitigationThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.