¡¾Îó²îͨ¸æ¡¿·ÉÀûÆÖ Vue PACS 7Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-07-13

0x00 Îó²î¸ÅÊö

2021Äê7ÔÂ6ÈÕ£¬£¬ £¬£¬ £¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö (CISA) Ðû²¼Ç徲ͨ¸æ£¬£¬ £¬£¬ £¬£¬Åû¶ÁË·ÉÀûÆÖ Vue Ò½ÁƲúÆ·ÖеÄ15¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î»áÓ°Ïì¶à¿î·ÉÀûÆÖÁÙ´²Ò½Ñ§Ð­×÷ƽ̨ÃÅ»§ (Vue PACS£©²úÆ·£¬£¬ £¬£¬ £¬£¬°üÀ¨ MyVue¡¢Vue Speech ºÍ Vue Motion µÈ¡£¡£¡£¡£¡£¡£¡£

·ÉÀûÆÖ Vue PACSÊôÓÚ¹«¹²Ò½ÁÆ¿µ½¡ÁìÓòµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÓÃʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë¡¢¸ü¸ÄϵͳµÄÔ¤ÆÚ¿ØÖÆÁ÷³Ì¡¢»á¼ûÃô¸ÐÐÅÏ¢»òµ¼ÖÂϵͳÍ߽⡣¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

ÔÚ±¾´ÎÅû¶µÄ15¸öÎó²îÖУ¬£¬ £¬£¬ £¬£¬¾ø´ó²¿·Ö¶¼¿É±»Ô¶³ÌʹÓ㬣¬ £¬£¬ £¬£¬²¢ÇÒ¹¥»÷ÖØÆ¯ºóµÍ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬ £¬£¬Óв¿·ÖÎó²î±£´æÓÚµÚÈý·½×é¼þÖУ¬£¬ £¬£¬ £¬£¬ÏêÇéÈçÏ£º

CVE ID

ÐÎò

CVSSÆÀ·Ö

ÊÇ·ñÔ¶³ÌʹÓÃ

¹¥»÷ÖØÆ¯ºó

CVE-2020-1938

²»×¼È·µÄÊäÈëÑéÖ¤¡£¡£¡£¡£¡£¡£¡£

9.8

ÊÇ

µÍ

CVE-2018-12326¡¢CVE-2018-11218

Äڴ滺³åÇø¹æÄ£ÄڵIJÙ×÷ÏÞÖÆ²»µ±¡£¡£¡£¡£¡£¡£¡£´ËÎó²î±£´æÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£¡£¡£¡£¡£¡£¡£

9.8

ÊÇ

µÍ

CVE-2020-4670

ÈÏÖ¤¹ýʧ¡£¡£¡£¡£¡£¡£¡£´ËÎó²î±£´æÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖС£¡£¡£¡£¡£¡£¡£

9.8

ÊÇ

µÍ

CVE-2018-8014

×ÊÔ´µÄ²»Ç徲ĬÈϳõʼ»¯¡£¡£¡£¡£¡£¡£¡£

9.8

ÊÇ

µÍ

CVE-2021-33020

ʹÓÃÓâÆÚµÄÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£

8.2

ÊÇ

µÍ

CVE-2018-10115

×ÊÔ´³õʼ»¯²»µ±¡£¡£¡£¡£¡£¡£¡£´ËÎó²î±£´æÓÚµÚÈý·½Èí¼þ×é¼þ (7-Zip) ÖС£¡£¡£¡£¡£¡£¡£

7.8

·ñ

µÍ

CVE-2021-27501

²»×¼È·×ñÊØ±àÂë±ê×¼¡£¡£¡£¡£¡£¡£¡£

7.5

ÊÇ

¸ß

CVE-2021-33018

ʹÓÃË𻵵ĻòÓÐΣº¦µÄÃÜÂëËã·¨£¬£¬ £¬£¬ £¬£¬¿ÉÄܻᵼÖÂÃô¸ÐÐÅϢ̻¶¡£¡£¡£¡£¡£¡£¡£

6.5

ÊÇ

¸ß

CVE-2021-27497

±£» £»£»£»£»£»£»£»¤»úÖÆÊ§Ð§¡£¡£¡£¡£¡£¡£¡£

6.5

ÊÇ

¸ß

CVE-2012-1708

Êý¾ÝÍêÕûÐÔÎÊÌâ¡£¡£¡£¡£¡£¡£¡£´ËÎó²î±£´æÓÚµÚÈý·½Èí¼þ×é¼þ£¨Oracle Êý¾Ý¿â£©ÖС£¡£¡£¡£¡£¡£¡£

6.5

ÊÇ

µÍ

CVE-2015-9251

XSS

6.1

ÊÇ

µÍ

CVE-2021-27493

²»¿ÉÈ·±£½á¹¹»¯ÐÂÎÅ»òÊý¾ÝÃûÌÃ׼ȷ²¢Öª×ãijЩÇå¾²ÊôÐÔ¡£¡£¡£¡£¡£¡£¡£

6.1

ÊÇ

µÍ

CVE-2019-9636

µ±ÊäÈë°üÀ¨ Unicode ±àÂëʱ£¬£¬ £¬£¬ £¬£¬Èí¼þÎÞ·¨×¼È·´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£

5.3

ÊÇ

µÍ

CVE-2021-33024

ʹÓò»Çå¾²µÄÒªÁì´«Êä»ò´æ´¢Éí·ÝÑé֤ƾ֤¡£¡£¡£¡£¡£¡£¡£

3.7

ÊÇ

¸ß

CVE-2021-33022

Ãô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£¡£¡£¡£¡£¡£¡£

7.5

ÊÇ

µÍ

 

Ó°Ïì¹æÄ£

Vue PACS <= 12.2.xx

Vue MyVue <= 12.2.xx

Vue Speech <= 12.2.xx

Vue Motion <=12.2.1.5

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ·ÉÀûÆÖÒÑÐû²¼Îó²îÐÞ¸´ÍýÏ룬£¬ £¬£¬ £¬£¬½¨Òé²Î¿¼CISA»ò·ÉÀûÆÖ¹Ù·½»ñÈ¡ÏêϸÐÅÏ¢£º

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01

https://www.usa.philips.com/healthcare/about/customer-support/product-security

 

»º½â²½·¥

l  Ö»¹ÜïÔÌ­ËùÓпØÖÆÏµÍ³×°±¸»òϵͳÔÚÍøÂçÉÏ̻¶£¬£¬ £¬£¬ £¬£¬²¢È·±£ËüÃDz»¿É´Ó Internet »á¼û¡£¡£¡£¡£¡£¡£¡£

l  ½«¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬ £¬£¬ £¬£¬²¢½«ÆäÓëÉÌÒµÍøÂç¸ôÀë¡£¡£¡£¡£¡£¡£¡£

l  µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬ £¬£¬ £¬£¬Ê¹ÓÃÇå¾²µÄÒªÁ죬£¬ £¬£¬ £¬£¬ÈçʹÓÃÐéÄâרÓÃÍøÂç (VPN)£¬£¬ £¬£¬ £¬£¬²¢È·±£ VPN¸üе½¿ÉÓõÄ×îа汾¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01

https://www.philips.com/a-w/security/security-advisories.html#security_advisories

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33020

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-12

Ê×´ÎÐû²¼

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¿­·¢k8

¹Ø×¢ÒÔϹ«Öںţ¬£¬ £¬£¬ £¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png