ÂÞÊÏÒ½ÁÆÆ÷е¶à¸ö¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-11-20

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-18561 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 6.5 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18562 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.0 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18563 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.0 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18564 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.3 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18565 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.2 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Accu-Chek Inform II Base Unit / Base Unit Hub¨C03.01.04֮ǰµÄËùÓа汾
Accu-Chek Inform II Instrument¨C03.06.00֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚ14000£©/ 04.03.00֮ǰµÄËùÓа汾£¨ÐòÁкŸßÓÚ14000£©
CoaguChek / cobas h232 Handheld Base Unit¨C03.01.04֮ǰµÄËùÓа汾
CoaguChek Pro II¨C04.03.00֮ǰµÄËùÓа汾
CoaguChek XS Plus¨C03.01.06֮ǰµÄËùÓа汾
CoaguChek XS Pro¨C03.01.06֮ǰµÄËùÓа汾
cobas h 232¨C03.01.03֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚKQ0400000»òKS0400000£©
cobas h 232¨C04.00.04֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚKQ0400000»òKS0400000£©
cobas h 232¨C04.00.04֮ǰµÄËùÓа汾£¨ÐòÁкŸßÓÚKQ0400000»òKS0400000£©


·ì϶¸ÅÊö


ÈðÊ¿½¡È«ÊÂÒµ¹«Ë¾ÂÞÊÏ£¨Roche£©Ò½ÁÆÕï¶Ï²¿ÃÅ·ÖÃäµÄ¼¸¿îÒ½ÁÆÆ÷еÖдæÔÚ¶à¸ö°²È«·ì϶ £¬¿ÉÄÜ»áÈû¼ÕßµÄÈËÉí°²È«Ãæ¶Ô·çÏÕ¡£
À´×ÔÒÔÉ«ÁÐÒ½ÁÆÉ豸°²È«ÆóÒµMedigateµÄ°²È«×êÑÐÔ±Niv Yehezkel·¢ÏÖ £¬ÓÉÂÞÊϳö²úµÄÈý¿îÒ½ÁÆÆ÷е´æÔÚÎå¸ö°²È«·ì϶¡£×ܵÄÀ´Ëµ £¬ÕâЩ·ì϶»áÓ°Ïìµ½Accu-ChekѪÌÇÒÇ¡¢¿¹ÄýÒ½ÖÎÒ½ÁÆ×¨ÒµÈËԱʹÓõÄCoaguChekÄýѪ¼ì²âÒÇÒÔ¼°Cobas±ãЯʽÊÖ³ÖѪҺ·ÖÎöÒÇ¡£
ÔÚÃÀ¹ú¹¤Òµ»¥ÁªÍø°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©×î½ü°ä²¼µÄÒ»·ÝÕ÷ѯÖÐ £¬ÎÒÃÇÄܹ»ÕÒµ½ËùÓÐÒ×Êܹ¥»÷µÄ²úÆ·ºÍ°æ±¾µÄ¾ßÌåÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Ã¿Ò»¸ö·ì϶³ÇÊÐÓ°ÏìÂÞÊÏÒ½ÁÆÆ÷еµÄ¶à¸öÐͺźͰ汾¡£
CVE-2018-18561£º·ìϼûèÊö£ºÈõ½Ó¼ûƾ֤·ì϶ £¬ÔÊÐí¹¥»÷ÕßÄܹ»Í¨¹ý·þÎñ½Ó¿ÚÀ´»ñµÃδ¾­ÊÚȨµÄ·þÎñ½Ó¼û¡£
CVE-2018-18562£º·ìϼûèÊö£ºOSºÅÁî×¢Èë·ì϶ £¬·þÎñ½Ó¿ÚÖеIJ»°²È«È¨ÏÞÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£
CVE-2018-18563£º·ìϼûèÊö£ºËÁÒâÎļþ¸²¸Ç·ì϶ £¬Èí¼þ¸üлúÔìÖеķì϶ÔÊÐí¹¥»÷Õßͨ¹ý¾«ÐÄÉè¼ÆµÄ¸üаü¸²¸ÇϵͳÉϵÄËÁÒâÎļþ¡£
CVE-2018-18564£º·ìϼûèÊö£ºËÁÒâ´úÂëÖ´Ðзì϶ £¬¶Ô·þÎñºÅÁîµÄ²»ÕýÈ·½Ó¼û½ÚÔìÔÊÐí¹¥»÷Õßͨ¹ý¾«ÐÄÔì×÷µÄÐÂÎÅÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
CVE-2018-18565£º·ìϼûèÊö£ºÅäÖÃËÁÒâÅú¸Ä·ì϶ £¬²»ÕýÈ·µÄ½Ó¼û½ÚÔìÔÊÐí¹¥»÷Õ߸ü¸ÄÒÇÆ÷ÅäÖá£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP


½¨¸´½¨Òé


ÂÞÊϽ¨Òé´ºÁªÍøÉ豸£¨ÒÔÌ«ÍøºÍWi-Fi£©²ÉÈ¡ÒÔÏ»º½â´ëÊ©£º
ͨ¹ýÆôÓÃÉ豸°²È«Ö°ÄÜ £¬Ï޶ȶÔÉ豸ºÍÏνӵĻù´¡¼Ü¹¹µÄÍøÂçºÍÎïÀí½Ó¼û¡£
±£»¤ÏνӵĶ˵ãÃâÊÜδ¾­ÊÚȨµÄ½Ó¼û¡¢ÍµÇԺͶñÒâÈí¼þµÄÇÖº¦¡£
¼à¿ØÏµÍ³ºÍÍøÂç»ù´¡ÉèÊ©ÊÇ·ñ´æÔÚ¿ÉÒɻ £¬²¢Æ¾¾Ý±¾µØÕþ²ßÏòÓйز¿ÃŽøÐл㱨¡£
¶ÔÓÚ·ÇÁªÍøÉ豸£º
Ô¤·Àδ¾­ÊÚȨµÄ½Ó¼û¡¢ÍµÇԺͰѳÖ¡£
¶ÔÓÚËùÓÐÊÜÓ°ÏìµÄ²úÆ· £¬ÂÞÊÏÒÑ´òËãÔÚ2018Äê11ÔÂÆðÍ·°ä²¼ÐµÄÈí¼þ¸üС£


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSMA-18-310-01
https://www.securityfocus.com/bid/105843