← Back

Philips

philips

115 CVEs • 169 products

Products (169)

Click to collapse
Toggle
Vue Pacs
vue_pacs
Myvue
myvue
Speech
speech
Vue Motion
vue_motion
Xcelera
xcelera
Dosewise
dosewise
Tasy Emr
tasy_emr
Xperconnect
xperconnect
Isite Pacs
isite_pacs
Tasy Webportal
tasy_webportal
Cx50 Firmware
cx50_firmware
Sparq Firmware
sparq_firmware
Smartcontrol
smartcontrol
Dreammapper
dreammapper
Hue Firmware
hue_firmware
Coronary Tools
coronary_tools
Viewforum
viewforum
Engage
engage
Encoreanywhere
encoreanywhere
Alice 6
alice_6

CVEs (115)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Philips
4Myvue
SpeechVue Motion+1 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.
1Philips
4Myvue
SpeechVue Motion+1 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
1Philips
4Myvue
SpeechVue Motion+1 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or...Show more
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.Show less
1Philips
1Engage
Jun 17, 2026
Jan 10, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.
1Philips
1Patient Information Center Ix
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.
1Philips
2Efficia Cm Firmware
Patient Information Center Ix
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects the communications between Patient Information Center iX (PIC iX) Versio...Show more
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects the communications between Patient Information Center iX (PIC iX) Versions C.02 and C.03 and Efficia CM Series Revisions A.01 to C.0x and 4.0.Show less
1Philips
1Patient Information Center Ix
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.
1Philips
2Intellibridge Ec40 Firmware
Intellibridge Ec80 Firmware
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.
1Philips
2Intellibridge Ec40 Firmware
Intellibridge Ec80 Firmware
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external componen...Show more
IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.Show less
1Philips
2Mri 1.5t Firmware
Mri 3t Firmware
Jun 17, 2026
Nov 19, 2021
5.9 MEDIUM· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
1Philips
2Mri 1.5t Firmware
Mri 3t Firmware
Jun 17, 2026
Nov 19, 2021
5.9 MEDIUM· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
1Philips
2Mri 1.5t Firmware
Mri 3t Firmware
Jun 17, 2026
Nov 19, 2021
5.9 MEDIUM· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
1Philips
1Tasy Electronic Medical Record
Jun 17, 2026
Aug 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.
1Philips
1Tasy Electronic Medical Record
Jun 17, 2026
Aug 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.
1Philips
5Coronary Tools
Dynamic Coronary RoadmapInterventional Workspot+2 more
Jun 17, 2026
Jan 26, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an...Show more
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.Show less
1Philips
1Hue Firmware
Jun 17, 2026
Dec 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. Du...Show more
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.Show less
1Philips
1Clinical Collaboration Platform
Jun 17, 2026
Sep 18, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
1Philips
1Clinical Collaboration Platform
Jun 17, 2026
Sep 18, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources co...Show more
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.Show less
1Philips
1Clinical Collaboration Platform
Jun 17, 2026
Sep 18, 2020
N/A· v4
6.3 MEDIUM· v3
5.8 MEDIUM· v2
When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficiently proves the claim is correct.
1Philips
1Clinical Collaboration Platform
Jun 17, 2026
Sep 18, 2020
N/A· v4
3.5 LOW· v3
2.7 LOW· v2
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.