¡¾·ì϶¹«¸æ¡¿·ÉÀûÆÖ Vue PACS 7Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-07-130x00 ·ì϶¸ÅÊö
2021Äê7ÔÂ6ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) °ä²¼°²È«²¼¸æ£¬Åû¶ÁË·ÉÀûÆÖ Vue Ò½ÁƲúÆ·ÖеÄ15¸ö°²È«·ì϶¡£ÕâЩ·ì϶»áÓ°Ïì¶à¿î·ÉÀûÆÖÁÙ´²Ò½Ñ§ºÏ×÷ƽ̨ÃÅ»§ (Vue PACS£©²úÆ·£¬Ô̺¬ MyVue¡¢Vue Speech ºÍ Vue Motion µÈ¡£
·ÉÀûÆÖ Vue PACSÊôÓÚ¹«¹²Ò½Áƽ¡È«ÁìÓòµÄ»ù´¡ÉèÊ©¡£Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÓÃÀûÓÃÕâЩ·ì϶ִÐÐËÁÒâ´úÂë¡¢¸ü¸ÄϵͳµÄÔ¤ÆÚ½ÚÔìÁ÷³Ì¡¢½Ó¼ûÃô¸ÐÐÅÏ¢»òµ¼ÖÂϵͳ±ÀÀ£¡£
0x01 ·ì϶ÏêÇé

ÔÚ±¾´ÎÅû¶µÄ15¸ö·ì϶ÖУ¬¾ø´ó²¿ÃŶ¼¿É±»Ô¶³ÌÀûÓ㬲¢ÇÒ¹¥»÷¸´ÔӶȵ͡£´Ë±í£¬Óв¿ÃÅ·ì϶´æÔÚÓÚµÚÈý·½×é¼þÖУ¬ÏêÇéÈçÏ£º
CVE ID | ÃèÊö | CVSSÆÀ·Ö | ÊÇ·ñÔ¶³ÌÀûÓà | ¹¥»÷¸´ÔÓ¶È |
CVE-2020-1938 | ²»ÕýÈ·µÄÊäÈëÑéÖ¤¡£ | 9.8 | ÊÇ | µÍ |
CVE-2018-12326¡¢CVE-2018-11218 | Äڴ滺³åÇøÁìÓòÄڵIJÙ×÷Ï޶Ȳ»µ±¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£ | 9.8 | ÊÇ | µÍ |
CVE-2020-4670 | ÈÏÖ¤ÃýÎó¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£ | 9.8 | ÊÇ | µÍ |
CVE-2018-8014 | ×ÊÔ´µÄ²»°²È«Ä¬Èϳõʼ»¯¡£ | 9.8 | ÊÇ | µÍ |
CVE-2021-33020 | ʹÓùýÆÚµÄÃÜÔ¿¡£ | 8.2 | ÊÇ | µÍ |
CVE-2018-10115 | ×ÊÔ´³õʼ»¯²»µ±¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (7-Zip) ÖС£ | 7.8 | ·ñ | µÍ |
CVE-2021-27501 | ²»ÕýÈ·×ñÊØ±àÂë³ß¶È¡£ | 7.5 | ÊÇ | ¸ß |
CVE-2021-33018 | ʹÓðܻµµÄ»òÓзçÏÕµÄÃÜÂëËã·¨£¬¿ÉÄܻᵼÖÂÃô¸ÐÐÅϢ¶³ö¡£ | 6.5 | ÊÇ | ¸ß |
CVE-2021-27497 | ±£»¤»úÔìʧЧ¡£ | 6.5 | ÊÇ | ¸ß |
CVE-2012-1708 | Êý¾ÝÆëÈ«ÐÔÎÊÌâ¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ£¨Oracle Êý¾Ý¿â£©ÖС£ | 6.5 | ÊÇ | µÍ |
CVE-2015-9251 | XSS | 6.1 | ÊÇ | µÍ |
CVE-2021-27493 | ²»ÄÜÈ·±£½á¹¹»¯ÐÂÎÅ»òÊý¾ÝÌåʽÕýÈ·²¢Âú×ãijЩ°²È«ÊôÐÔ¡£ | 6.1 | ÊÇ | µÍ |
CVE-2019-9636 | µ±ÊäÈëÔ̺¬ Unicode ±àÂëʱ£¬Èí¼þÎÞ·¨ÕýÈ·´¦Öᣠ| 5.3 | ÊÇ | µÍ |
CVE-2021-33024 | ʹÓò»°²È«µÄ²½Öè´«Êä»ò´æ´¢Éí·ÝÑé֤ƾ֤¡£ | 3.7 | ÊÇ | ¸ß |
CVE-2021-33022 | Ãô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£ | 7.5 | ÊÇ | µÍ |
Ó°ÏìÁìÓò
Vue PACS <= 12.2.xx
Vue MyVue <= 12.2.xx
Vue Speech <= 12.2.xx
Vue Motion <=12.2.1.5
0x02 ´ëÖý¨Òé
Ŀǰ·ÉÀûÆÖÒѰ䲼·ì϶½¨¸´´òË㣬½¨Òé²Î¿¼CISA»ò·ÉÀûÆÖ¹Ù·½»ñÈ¡¾ßÌåÐÅÏ¢£º
https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01
https://www.usa.philips.com/healthcare/about/customer-support/product-security
»º½â´ëÊ©
l ¾¡Á¿Ï÷¼õËùÓнÚÔìϵͳÉ豸»òϵͳÔÚÍøÂçÉ϶³ö£¬²¢È·±£ËüÃDz»ÄÜ´Ó Internet ½Ó¼û¡£
l ½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬²¢½«ÆäÓëóÒ×ÍøÂç¸ôÀë¡£
l µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬Ê¹Óð²È«µÄ²½Ö裬ÈçʹÓÃÐ鹹רÓÃÍøÂç (VPN)£¬²¢È·±£ VPN¸üе½¿ÉÓõÄ×îа汾¡£
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01
https://www.philips.com/a-w/security/security-advisories.html#security_advisories
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33020
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-07-12 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ