CVE-2021-26248: medium-severity vulnerability in Philips MRI 1.5T
Philips MRI 1.5T and 3T Incorrect Ownership Assignment
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Philips MRI machines (versions 5.3-5.8.1) have a security flaw that allows unauthorized people to access medical imaging resources they shouldn't be able to reach. This is dangerous because it could expose sensitive patient data or allow tampering with critical medical equipment.
CWE-708 vulnerability in Philips MRI 1.5T and 3T systems fails to properly enforce access control on medical imaging resources. An unauthorized actor can access restricted resources without proper authentication or authorization checks, potentially compromising patient data confidentiality and system integrity.
In the same product, most dangerous first.