VYPR
Medium severity6.5NVD Advisory· Published Dec 26, 2022· Updated Jun 17, 2026

CVE-2021-39369

CVE-2021-39369

Description

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

Affected products

6
  • cpe:2.3:a:philips:myvue:-:*:*:*:*:*:*:*
  • cpe:2.3:a:philips:speech:-:*:*:*:*:*:*:*
  • cpe:2.3:a:philips:vue_motion:*:*:*:*:*:*:*:*
    Range: <=12.2.1.5
  • Philips/Vue Pacs2 versions
    cpe:2.3:a:philips:vue_pacs:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:philips:vue_pacs:-:*:*:*:*:*:*:*
    • (no CPE)range: <=12.2.x.x
  • Philips/Vue MyVue PACSdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.