Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.
Fixes

Solution

No solution given by the vendor.


Workaround

Philips has identified the following guidance and mitigations: Users should operate all Philips deployed and supported Gemini PET/CT systems within Philips authorized specifications, including Philips approved software, software configuration, system services, and security configuration. Philips also recommends users implement a comprehensive, multi-layered strategy to protect systems from internal and external security threats, including restricting physical access of the scanner and removable media to only authorized personnel to reduce the risk of physical access by an unauthorized user. Patient health related information recorded on removable media may become accessible to unauthorized individuals despite the application of the anonymize function, which could create a security risk. Users with questions regarding their specific installations of the Gemini PET/CT Family should contact a Philips service support team. Philips contact information is available at https://www.usa.philips.com/healthcare/solutions/customer-service-solutions or 1-800-722-9377 The Philips advisory is available. Please see the Philips product security website for the latest security information for Philips products.

History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:41:17.401Z

Reserved: 2021-02-19T00:00:00.000Z

Link: CVE-2021-27456

cve-icon Vulnrichment

Updated: 2024-08-03T20:48:17.180Z

cve-icon NVD

Status : Modified

Published: 2022-03-23T20:15:08.643

Modified: 2024-11-21T05:58:01.547

Link: CVE-2021-27456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.