Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSMA-18-312-01 | third party advisory us government resource |
http://www.securityfocus.com/bid/105875 | vdb entry third party advisory |