¡¾Â©¶´Í¨¸æ¡¿·ÉÀûÆÖ Vue PACS 7Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2021-07-130x00 ©¶´¸ÅÊö
2021Äê7ÔÂ6ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö (CISA) Ðû²¼Äþ¾²Í¨¸æ£¬Åû¶ÁË·ÉÀûÆÖ Vue Ò½ÁƲúÎïÖеÄ15¸öÄþ¾²Â©¶´¡£ÕâЩ©¶´»áÓ°Ïì¶à¿î·ÉÀûÆÖÁÙ´²Ò½Ñ§Ð×÷ƽ̨ÃÅ»§ (Vue PACS£©²úÎ°üÂÞ MyVue¡¢Vue Speech ºÍ Vue Motion µÈ¡£
·ÉÀûÆÖ Vue PACSÊôÓÚ¹«¹²Ò½Áƽ¡¿µÁìÓòµÄ»ù´¡ÉèÊ©¡£Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÓÃÀûÓÃÕâЩ©¶´Ö´ÐÐÈÎÒâ´úÂë¡¢¸ü¸ÄϵͳµÄÔ¤ÆÚ¿ØÖÆÁ÷³Ì¡¢·ÃÎÊÃô¸ÐÐÅÏ¢»òµ¼ÖÂϵͳÍ߽⡣
0x01 ©¶´ÏêÇé
ÔÚ±¾´ÎÅû¶µÄ15¸ö©¶´ÖУ¬¾ø´ó²¿ÃŶ¼¿É±»Ô¶³ÌÀûÓ㬶øÇÒ¹¥»÷ÅÓ´ó¶ÈµÍ¡£´ËÍ⣬Óв¿ÃÅ©¶´´æÔÚÓÚµÚÈý·½×é¼þÖУ¬ÏêÇéÈçÏ£º
CVE ID | ÃèÊö | CVSSÆÀ·Ö | ÊÇ·ñÔ¶³ÌÀûÓà | ¹¥»÷ÅÓ´ó¶È |
CVE-2020-1938 | ²»ÕýÈ·µÄÊäÈëÑéÖ¤¡£ | 9.8 | ÊÇ | µÍ |
CVE-2018-12326¡¢CVE-2018-11218 | Äڴ滺³åÇø·¶Î§ÄڵIJÙ×÷ÏÞÖÆ²»Íס£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£ | 9.8 | ÊÇ | µÍ |
CVE-2020-4670 | ÈÏÖ¤´íÎó¡£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£ | 9.8 | ÊÇ | µÍ |
CVE-2018-8014 | ×ÊÔ´µÄ²»Äþ¾²Ä¬Èϳõʼ»¯¡£ | 9.8 | ÊÇ | µÍ |
CVE-2021-33020 | ʹÓùýÆÚµÄÃÜÔ¿¡£ | 8.2 | ÊÇ | µÍ |
CVE-2018-10115 | ×ÊÔ´³õʼ»¯²»Íס£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (7-Zip) ÖС£ | 7.8 | ·ñ | µÍ |
CVE-2021-27501 | ²»ÕýÈ·×ñÊØ±àÂë³ß¶È¡£ | 7.5 | ÊÇ | ¸ß |
CVE-2021-33018 | ʹÓÃË𻵵ĻòÓзçÏÕµÄÃÜÂëËã·¨£¬¿ÉÄܻᵼÖÂÃô¸ÐÐÅϢ̻¶¡£ | 6.5 | ÊÇ | ¸ß |
CVE-2021-27497 | ±£»¤»úÖÆÊ§Ð§¡£ | 6.5 | ÊÇ | ¸ß |
CVE-2012-1708 | Êý¾ÝÍêÕûÐÔÎÊÌâ¡£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ£¨Oracle Êý¾Ý¿â£©ÖС£ | 6.5 | ÊÇ | µÍ |
CVE-2015-9251 | XSS | 6.1 | ÊÇ | µÍ |
CVE-2021-27493 | ²»ÄÜÈ·±£½á¹¹»¯ÏûÏ¢»òÊý¾Ý¸ñʽÕýÈ·²¢Âú×ãijЩÄþ¾²ÊôÐÔ¡£ | 6.1 | ÊÇ | µÍ |
CVE-2019-9636 | µ±ÊäÈë°üÂÞ Unicode ±àÂëʱ£¬Èí¼þÎÞ·¨ÕýÈ·´¦Öᣠ| 5.3 | ÊÇ | µÍ |
CVE-2021-33024 | ʹÓò»Äþ¾²µÄÒªÁì´«Êä»ò´æ´¢Éí·ÝÑé֤ƾ֤¡£ | 3.7 | ÊÇ | ¸ß |
CVE-2021-33022 | Ãô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£ | 7.5 | ÊÇ | µÍ |
Ó°Ï췶Χ
Vue PACS <= 12.2.xx
Vue MyVue <= 12.2.xx
Vue Speech <= 12.2.xx
Vue Motion <=12.2.1.5
0x02 ´¦Öý¨Òé
Ŀǰ·ÉÀûÆÖÒÑÐû²¼Â©¶´ÐÞ¸´¼Æ»®£¬½¨Òé²Î¿¼CISA»ò·ÉÀûÆÖ¹Ù·½»ñÈ¡ÏêϸÐÅÏ¢£º
https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01
https://www.usa.philips.com/healthcare/about/customer-support/product-security
»º½â´ëÊ©
l ¾¡Á¿¼õÉÙËùÓпØÖÆÏµÍ³É豸»òϵͳÔÚÍøÂçÉÏ̻¶£¬²¢È·±£ËüÃDz»ÄÜ´Ó Internet ·ÃÎÊ¡£
l ½«¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬²¢½«ÆäÓëÉÌÒµÍøÂç¸ôÀë¡£
l µ±ÐèÒªÔ¶³Ì·ÃÎÊʱ£¬Ê¹ÓÃÄþ¾²µÄÒªÁ죬ÈçʹÓÃÐéÄâרÓÃÍøÂç (VPN)£¬²¢È·±£ VPN¸üе½¿ÉÓõÄ×îа汾¡£
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01
https://www.philips.com/a-w/security/security-advisories.html#security_advisories
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33020
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-12 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶«Éƽ̨
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º