Philips Vue PACS before 12.2.8.410 — vendor advisory published through CISA (ICSMA-24-200-01)
Why this is on the list
Vendor-confirmed: affected range, remediation and fixed version come from the vendor or CNA advisory.
Picture archiving and communication system storing and distributing diagnostic imaging studies tied to identified patients. Availability and integrity affect diagnosis and imaging workflow.
Does this apply to your version?
An affected range is on record, derived from CISA's exploitation evidence rather than published by the product's vendor. Check your own release against it, or enter it in the lookup and Patient Protect will evaluate it for you.
Affected: <12.2.8.410 · Fixed in 12.2.8.410
Check your versionWhat to do
Update Vue PACS to version 12.2.8.410 or later and configure the Vue PACS environment per Philips document D000763414 (Vue PACS 12 Ports, Protocols and Services Guide). For CVE-2023-40704 Philips states no action is required, but customers may request that Philips update database passwords.
- Vendor
- Philips
- Product
- Vue PACS
- Affected versions
- <12.2.8.410
- Fixed in
- 12.2.8.410
- First published
- 2026-09-08
Where this comes from
2 sources- CISA
Source assertion: affected_range:cisa
Read the CISA record - CISA
Source assertion: vendor_fix
Read the CISA record
How this was assessed
- CISA medical advisory ICSMA-24-200-01 records Philips Vue PACS versions before 12.2.8.410 as affected by CVE-2021-28165 and CVE-2023-40704. Philips' remediation is Vue PACS 12.2.8.410, together with configuring the environment per Philips document D000763414. Neither CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.
Do you run this?
Check your own version against the ledger — it may or may not fall inside the affected range.
Check your technology