¡¾·ì϶¹«¸æ¡¿·ÉÀûÆÖ Vue PACS 7Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-07-13

0x00 ·ì϶¸ÅÊö

2021Äê7ÔÂ6ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) °ä²¼°²È«²¼¸æ £¬Åû¶ÁË·ÉÀûÆÖ Vue Ò½ÁƲúÆ·ÖеÄ15¸ö°²È«·ì϶¡£ÕâЩ·ì϶»áÓ°Ïì¶à¿î·ÉÀûÆÖÁÙ´²Ò½Ñ§ºÏ×÷ƽ̨ÃÅ»§ (Vue PACS£©²úÆ· £¬Ô̺¬ MyVue¡¢Vue Speech ºÍ Vue Motion µÈ¡£

·ÉÀûÆÖ Vue PACSÊôÓÚ¹«¹²Ò½Áƽ¡È«ÁìÓòµÄ»ù´¡ÉèÊ©¡£Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÓÃÀûÓÃÕâЩ·ì϶ִÐÐËÁÒâ´úÂë¡¢¸ü¸ÄϵͳµÄÔ¤ÆÚ½ÚÔìÁ÷³Ì¡¢½Ó¼ûÃô¸ÐÐÅÏ¢»òµ¼ÖÂϵͳ±ÀÀ£¡£

 

0x01 ·ì϶ÏêÇé

image.png

ÔÚ±¾´ÎÅû¶µÄ15¸ö·ì϶ÖÐ £¬¾ø´ó²¿ÃŶ¼¿É±»Ô¶³ÌÀûÓà £¬²¢ÇÒ¹¥»÷¸´ÔӶȵÍ¡£´Ë±í £¬Óв¿ÃÅ·ì϶´æÔÚÓÚµÚÈý·½×é¼þÖÐ £¬ÏêÇéÈçÏ£º

CVE ID

ÃèÊö

CVSSÆÀ·Ö

ÊÇ·ñÔ¶³ÌÀûÓÃ

¹¥»÷¸´ÔÓ¶È

CVE-2020-1938

²»ÕýÈ·µÄÊäÈëÑéÖ¤¡£

9.8

ÊÇ

µÍ

CVE-2018-12326¡¢CVE-2018-11218

Äڴ滺³åÇøÁìÓòÄڵIJÙ×÷Ï޶Ȳ»µ±¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£

9.8

ÊÇ

µÍ

CVE-2020-4670

ÈÏÖ¤ÃýÎó¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£

9.8

ÊÇ

µÍ

CVE-2018-8014

×ÊÔ´µÄ²»°²È«Ä¬Èϳõʼ»¯¡£

9.8

ÊÇ

µÍ

CVE-2021-33020

ʹÓùýÆÚµÄÃÜÔ¿¡£

8.2

ÊÇ

µÍ

CVE-2018-10115

×ÊÔ´³õʼ»¯²»µ±¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (7-Zip) ÖС£

7.8

·ñ

µÍ

CVE-2021-27501

²»ÕýÈ·×ñÊØ±àÂë³ß¶È¡£

7.5

ÊÇ

¸ß

CVE-2021-33018

ʹÓðܻµµÄ»òÓзçÏÕµÄÃÜÂëËã·¨ £¬¿ÉÄܻᵼÖÂÃô¸ÐÐÅϢ¶³ö¡£

6.5

ÊÇ

¸ß

CVE-2021-27497

±£»¤»úÔìʧЧ¡£

6.5

ÊÇ

¸ß

CVE-2012-1708

Êý¾ÝÆëÈ«ÐÔÎÊÌâ¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ£¨Oracle Êý¾Ý¿â£©ÖС£

6.5

ÊÇ

µÍ

CVE-2015-9251

XSS

6.1

ÊÇ

µÍ

CVE-2021-27493

²»ÄÜÈ·±£½á¹¹»¯ÐÂÎÅ»òÊý¾ÝÌåʽÕýÈ·²¢Âú×ãijЩ°²È«ÊôÐÔ¡£

6.1

ÊÇ

µÍ

CVE-2019-9636

µ±ÊäÈëÔ̺¬ Unicode ±àÂëʱ £¬Èí¼þÎÞ·¨ÕýÈ·´¦Öá£

5.3

ÊÇ

µÍ

CVE-2021-33024

ʹÓò»°²È«µÄ²½Öè´«Êä»ò´æ´¢Éí·ÝÑé֤ƾ֤¡£

3.7

ÊÇ

¸ß

CVE-2021-33022

Ãô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£

7.5

ÊÇ

µÍ

 

Ó°ÏìÁìÓò

Vue PACS <= 12.2.xx

Vue MyVue <= 12.2.xx

Vue Speech <= 12.2.xx

Vue Motion <=12.2.1.5

 

0x02 ´ëÖý¨Òé

Ŀǰ·ÉÀûÆÖÒѰ䲼·ì϶½¨¸´´òËã £¬½¨Òé²Î¿¼CISA»ò·ÉÀûÆÖ¹Ù·½»ñÈ¡¾ßÌåÐÅÏ¢£º

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01

https://www.usa.philips.com/healthcare/about/customer-support/product-security

 

»º½â´ëÊ©

l  ¾¡Á¿Ï÷¼õËùÓнÚÔìϵͳÉ豸»òϵͳÔÚÍøÂçÉ϶³ö £¬²¢È·±£ËüÃDz»ÄÜ´Ó Internet ½Ó¼û¡£

l  ½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó £¬²¢½«ÆäÓëóÒ×ÍøÂç¸ôÀë¡£

l  µ±±ØÒªÔ¶³Ì½Ó¼ûʱ £¬Ê¹Óð²È«µÄ²½Öè £¬ÈçʹÓÃÐ鹹רÓÃÍøÂç (VPN) £¬²¢È·±£ VPN¸üе½¿ÉÓõÄ×îа汾¡£

 

0x03 ²Î¿¼Á´½Ó

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01

https://www.philips.com/a-w/security/security-advisories.html#security_advisories

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33020

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-07-12

³õ´Î°ä²¼

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ £¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png