Philips · Philips Vue Myvue Pacs · CVE-2021-39369
**Name of the Vulnerable Software and Affected Versions**
Philips Vue MyVue PACS versions prior to 12.2.x.x
**Description**
The issue allows authenticated users to perform Path Traversal, accessing files stored outside of the web root through the VideoStream function.
**Recommendations**
For Philips Vue MyVue PACS versions prior to 12.2.x.x, as a temporary workaround, consider disabling the `VideoStream` function until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation.