¡¾Â©¶´Í¨¸æ¡¿·ÉÀûÆÖ Vue PACS 7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-07-13

0x00 ©¶´¸ÅÊö

2021Äê7ÔÂ6ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö (CISA) Ðû²¼Äþ¾²Í¨¸æ£¬Åû¶ÁË·ÉÀûÆÖ Vue Ò½ÁƲúÎïÖеÄ15¸öÄþ¾²Â©¶´¡£ÕâЩ©¶´»áÓ°Ïì¶à¿î·ÉÀûÆÖÁÙ´²Ò½Ñ§Ð­×÷ƽ̨ÃÅ»§ (Vue PACS£©²úÎ°üÂÞ MyVue¡¢Vue Speech ºÍ Vue Motion µÈ¡£

·ÉÀûÆÖ Vue PACSÊôÓÚ¹«¹²Ò½Áƽ¡¿µÁìÓòµÄ»ù´¡ÉèÊ©¡£Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÓÃÀûÓÃÕâЩ©¶´Ö´ÐÐÈÎÒâ´úÂë¡¢¸ü¸ÄϵͳµÄÔ¤ÆÚ¿ØÖÆÁ÷³Ì¡¢·ÃÎÊÃô¸ÐÐÅÏ¢»òµ¼ÖÂϵͳÍ߽⡣

 

0x01 ©¶´ÏêÇé

image.png

ÔÚ±¾´ÎÅû¶µÄ15¸ö©¶´ÖУ¬¾ø´ó²¿ÃŶ¼¿É±»Ô¶³ÌÀûÓ㬶øÇÒ¹¥»÷ÅÓ´ó¶ÈµÍ¡£´ËÍ⣬Óв¿ÃÅ©¶´´æÔÚÓÚµÚÈý·½×é¼þÖУ¬ÏêÇéÈçÏ£º

CVE ID

ÃèÊö

CVSSÆÀ·Ö

ÊÇ·ñÔ¶³ÌÀûÓÃ

¹¥»÷ÅÓ´ó¶È

CVE-2020-1938

²»ÕýÈ·µÄÊäÈëÑéÖ¤¡£

9.8

ÊÇ

µÍ

CVE-2018-12326¡¢CVE-2018-11218

Äڴ滺³åÇø·¶Î§ÄڵIJÙ×÷ÏÞÖÆ²»Íס£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£

9.8

ÊÇ

µÍ

CVE-2020-4670

ÈÏÖ¤´íÎó¡£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£

9.8

ÊÇ

µÍ

CVE-2018-8014

×ÊÔ´µÄ²»Äþ¾²Ä¬Èϳõʼ»¯¡£

9.8

ÊÇ

µÍ

CVE-2021-33020

ʹÓùýÆÚµÄÃÜÔ¿¡£

8.2

ÊÇ

µÍ

CVE-2018-10115

×ÊÔ´³õʼ»¯²»Íס£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (7-Zip) ÖС£

7.8

·ñ

µÍ

CVE-2021-27501

²»ÕýÈ·×ñÊØ±àÂë³ß¶È¡£

7.5

ÊÇ

¸ß

CVE-2021-33018

ʹÓÃË𻵵ĻòÓзçÏÕµÄÃÜÂëËã·¨£¬¿ÉÄܻᵼÖÂÃô¸ÐÐÅϢ̻¶¡£

6.5

ÊÇ

¸ß

CVE-2021-27497

±£»¤»úÖÆÊ§Ð§¡£

6.5

ÊÇ

¸ß

CVE-2012-1708

Êý¾ÝÍêÕûÐÔÎÊÌâ¡£´Ë©¶´´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ£¨Oracle Êý¾Ý¿â£©ÖС£

6.5

ÊÇ

µÍ

CVE-2015-9251

XSS

6.1

ÊÇ

µÍ

CVE-2021-27493

²»ÄÜÈ·±£½á¹¹»¯ÏûÏ¢»òÊý¾Ý¸ñʽÕýÈ·²¢Âú×ãijЩÄþ¾²ÊôÐÔ¡£

6.1

ÊÇ

µÍ

CVE-2019-9636

µ±ÊäÈë°üÂÞ Unicode ±àÂëʱ£¬Èí¼þÎÞ·¨ÕýÈ·´¦Öá£

5.3

ÊÇ

µÍ

CVE-2021-33024

ʹÓò»Äþ¾²µÄÒªÁì´«Êä»ò´æ´¢Éí·ÝÑé֤ƾ֤¡£

3.7

ÊÇ

¸ß

CVE-2021-33022

Ãô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£

7.5

ÊÇ

µÍ

 

Ó°Ï췶Χ

Vue PACS <= 12.2.xx

Vue MyVue <= 12.2.xx

Vue Speech <= 12.2.xx

Vue Motion <=12.2.1.5

 

0x02 ´¦Öý¨Òé

Ŀǰ·ÉÀûÆÖÒÑÐû²¼Â©¶´ÐÞ¸´¼Æ»®£¬½¨Òé²Î¿¼CISA»ò·ÉÀûÆÖ¹Ù·½»ñÈ¡ÏêϸÐÅÏ¢£º

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01

https://www.usa.philips.com/healthcare/about/customer-support/product-security

 

»º½â´ëÊ©

l  ¾¡Á¿¼õÉÙËùÓпØÖÆÏµÍ³É豸»òϵͳÔÚÍøÂçÉÏ̻¶£¬²¢È·±£ËüÃDz»ÄÜ´Ó Internet ·ÃÎÊ¡£

l  ½«¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬²¢½«ÆäÓëÉÌÒµÍøÂç¸ôÀë¡£

l  µ±ÐèÒªÔ¶³Ì·ÃÎÊʱ£¬Ê¹ÓÃÄþ¾²µÄÒªÁ죬ÈçʹÓÃÐéÄâרÓÃÍøÂç (VPN)£¬²¢È·±£ VPN¸üе½¿ÉÓõÄ×îа汾¡£

 

0x03 ²Î¿¼Á´½Ó

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01

https://www.philips.com/a-w/security/security-advisories.html#security_advisories

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33020

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-12

Ê×´ÎÐû²¼

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png