¡¾·ì϶¹«¸æ¡¿·ÉÀûÆÖ Vue PACS 7Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-07-130x00 ·ì϶¸ÅÊö
2021Äê7ÔÂ6ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) °ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬Åû¶ÁË·ÉÀûÆÖ Vue Ò½ÁƲúÆ·ÖеÄ15¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶»áÓ°Ïì¶à¿î·ÉÀûÆÖÁÙ´²Ò½Ñ§ºÏ×÷ƽ̨ÃÅ»§ (Vue PACS£©²úÆ·£¬£¬£¬£¬£¬Ô̺¬ MyVue¡¢Vue Speech ºÍ Vue Motion µÈ¡£¡£¡£¡£¡£¡£¡£
·ÉÀûÆÖ Vue PACSÊôÓÚ¹«¹²Ò½Áƽ¡È«ÁìÓòµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÓÃÀûÓÃÕâЩ·ì϶ִÐÐËÁÒâ´úÂë¡¢¸ü¸ÄϵͳµÄÔ¤ÆÚ½ÚÔìÁ÷³Ì¡¢½Ó¼ûÃô¸ÐÐÅÏ¢»òµ¼ÖÂϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

ÔÚ±¾´ÎÅû¶µÄ15¸ö·ì϶ÖУ¬£¬£¬£¬£¬¾ø´ó²¿ÃŶ¼¿É±»Ô¶³ÌÀûÓ㬣¬£¬£¬£¬²¢ÇÒ¹¥»÷¸´ÔӶȵ͡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Óв¿ÃÅ·ì϶´æÔÚÓÚµÚÈý·½×é¼þÖУ¬£¬£¬£¬£¬ÏêÇéÈçÏ£º
CVE ID | ÃèÊö | CVSSÆÀ·Ö | ÊÇ·ñÔ¶³ÌÀûÓà | ¹¥»÷¸´ÔÓ¶È |
CVE-2020-1938 | ²»ÕýÈ·µÄÊäÈëÑéÖ¤¡£¡£¡£¡£¡£¡£¡£ | 9.8 | ÊÇ | µÍ |
CVE-2018-12326¡¢CVE-2018-11218 | Äڴ滺³åÇøÁìÓòÄڵIJÙ×÷Ï޶Ȳ»µ±¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖÓ×£¡£¡£¡£¡£¡£¡£ | 9.8 | ÊÇ | µÍ |
CVE-2020-4670 | ÈÏÖ¤ÃýÎ󡣡£¡£¡£¡£¡£¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (Redis) ÖÓ×£¡£¡£¡£¡£¡£¡£ | 9.8 | ÊÇ | µÍ |
CVE-2018-8014 | ×ÊÔ´µÄ²»°²È«Ä¬Èϳõʼ»¯¡£¡£¡£¡£¡£¡£¡£ | 9.8 | ÊÇ | µÍ |
CVE-2021-33020 | ʹÓùýÆÚµÄÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£ | 8.2 | ÊÇ | µÍ |
CVE-2018-10115 | ×ÊÔ´³õʼ»¯²»µ±¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ (7-Zip) ÖÓ×£¡£¡£¡£¡£¡£¡£ | 7.8 | ·ñ | µÍ |
CVE-2021-27501 | ²»ÕýÈ·×ñÊØ±àÂë³ß¶È¡£¡£¡£¡£¡£¡£¡£ | 7.5 | ÊÇ | ¸ß |
CVE-2021-33018 | ʹÓðܻµµÄ»òÓзçÏÕµÄÃÜÂëËã·¨£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂÃô¸ÐÐÅϢ¶³ö¡£¡£¡£¡£¡£¡£¡£ | 6.5 | ÊÇ | ¸ß |
CVE-2021-27497 | ±£»£»£»£»£»¤»úÔìʧЧ¡£¡£¡£¡£¡£¡£¡£ | 6.5 | ÊÇ | ¸ß |
CVE-2012-1708 | Êý¾ÝÆëÈ«ÐÔÎÊÌâ¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶´æÔÚÓÚµÚÈý·½Èí¼þ×é¼þ£¨Oracle Êý¾Ý¿â£©ÖÓ×£¡£¡£¡£¡£¡£¡£ | 6.5 | ÊÇ | µÍ |
CVE-2015-9251 | XSS | 6.1 | ÊÇ | µÍ |
CVE-2021-27493 | ²»ÄÜÈ·±£½á¹¹»¯ÐÂÎÅ»òÊý¾ÝÌåʽÕýÈ·²¢Âú×ãijЩ°²È«ÊôÐÔ¡£¡£¡£¡£¡£¡£¡£ | 6.1 | ÊÇ | µÍ |
CVE-2019-9636 | µ±ÊäÈëÔ̺¬ Unicode ±àÂëʱ£¬£¬£¬£¬£¬Èí¼þÎÞ·¨ÕýÈ·´¦Öᣡ£¡£¡£¡£¡£¡£ | 5.3 | ÊÇ | µÍ |
CVE-2021-33024 | ʹÓò»°²È«µÄ²½Öè´«Êä»ò´æ´¢Éí·ÝÑé֤ƾ֤¡£¡£¡£¡£¡£¡£¡£ | 3.7 | ÊÇ | ¸ß |
CVE-2021-33022 | Ãô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä¡£¡£¡£¡£¡£¡£¡£ | 7.5 | ÊÇ | µÍ |
Ó°ÏìÁìÓò
Vue PACS <= 12.2.xx
Vue MyVue <= 12.2.xx
Vue Speech <= 12.2.xx
Vue Motion <=12.2.1.5
0x02 ´ëÖý¨Òé
Ŀǰ·ÉÀûÆÖÒѰ䲼·ì϶½¨¸´´òË㣬£¬£¬£¬£¬½¨Òé²Î¿¼CISA»ò·ÉÀûÆÖ¹Ù·½»ñÈ¡¾ßÌåÐÅÏ¢£º
https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01
https://www.usa.philips.com/healthcare/about/customer-support/product-security
»º½â´ëÊ©
l ¾¡Á¿Ï÷¼õËùÓнÚÔìϵͳÉ豸»òϵͳÔÚÍøÂçÉ϶³ö£¬£¬£¬£¬£¬²¢È·±£ËüÃDz»ÄÜ´Ó Internet ½Ó¼û¡£¡£¡£¡£¡£¡£¡£
l ½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬£¬£¬£¬²¢½«ÆäÓëóÒ×ÍøÂç¸ôÀë¡£¡£¡£¡£¡£¡£¡£
l µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬£¬£¬£¬£¬Ê¹Óð²È«µÄ²½Ö裬£¬£¬£¬£¬ÈçʹÓÃÐ鹹רÓÃÍøÂç (VPN)£¬£¬£¬£¬£¬²¢È·±£ VPN¸üе½¿ÉÓõÄ×îа汾¡£¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsma-21-187-01
https://www.philips.com/a-w/security/security-advisories.html#security_advisories
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33020
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-07-12 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ