ÂÞÊÏÒ½ÁÆÆ÷е¶à¸ö¸ßΣ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-11-20·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-18561£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 6.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18562£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.0£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18563£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.0£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18564£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.3£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18565£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.2£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Accu-Chek Inform II Base Unit / Base Unit Hub¨C03.01.04֮ǰµÄËùÓа汾
Accu-Chek Inform II Instrument¨C03.06.00֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚ14000£©/ 04.03.00֮ǰµÄËùÓа汾£¨ÐòÁкŸßÓÚ14000£©
CoaguChek / cobas h232 Handheld Base Unit¨C03.01.04֮ǰµÄËùÓа汾
CoaguChek Pro II¨C04.03.00֮ǰµÄËùÓа汾
CoaguChek XS Plus¨C03.01.06֮ǰµÄËùÓа汾
CoaguChek XS Pro¨C03.01.06֮ǰµÄËùÓа汾
cobas h 232¨C03.01.03֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚKQ0400000»òKS0400000£©
cobas h 232¨C04.00.04֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚKQ0400000»òKS0400000£©
cobas h 232¨C04.00.04֮ǰµÄËùÓа汾£¨ÐòÁкŸßÓÚKQ0400000»òKS0400000£©
·ì϶¸ÅÊö
ÈðÊ¿½¡È«ÊÂÒµ¹«Ë¾ÂÞÊÏ£¨Roche£©Ò½ÁÆÕï¶Ï²¿ÃÅ·ÖÃäµÄ¼¸¿îÒ½ÁÆÆ÷еÖдæÔÚ¶à¸ö°²È«·ì϶£¬¿ÉÄÜ»áÈû¼ÕßµÄÈËÉí°²È«Ãæ¶Ô·çÏÕ¡£
À´×ÔÒÔÉ«ÁÐÒ½ÁÆÉ豸°²È«ÆóÒµMedigateµÄ°²È«×êÑÐÔ±Niv Yehezkel·¢ÏÖ£¬ÓÉÂÞÊϳö²úµÄÈý¿îÒ½ÁÆÆ÷е´æÔÚÎå¸ö°²È«·ì϶¡£×ܵÄÀ´Ëµ£¬ÕâЩ·ì϶»áÓ°Ïìµ½Accu-ChekѪÌÇÒÇ¡¢¿¹ÄýÒ½ÖÎÒ½ÁÆ×¨ÒµÈËԱʹÓõÄCoaguChekÄýѪ¼ì²âÒÇÒÔ¼°Cobas±ãЯʽÊÖ³ÖѪҺ·ÖÎöÒÇ¡£
ÔÚÃÀ¹ú¹¤Òµ»¥ÁªÍø°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©×î½ü°ä²¼µÄÒ»·ÝÕ÷ѯÖУ¬ÎÒÃÇÄܹ»ÕÒµ½ËùÓÐÒ×Êܹ¥»÷µÄ²úÆ·ºÍ°æ±¾µÄ¾ßÌåÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Ã¿Ò»¸ö·ì϶³ÇÊÐÓ°ÏìÂÞÊÏÒ½ÁÆÆ÷еµÄ¶à¸öÐͺźͰ汾¡£
CVE-2018-18561£º·ìϼûèÊö£ºÈõ½Ó¼ûƾ֤·ì϶£¬ÔÊÐí¹¥»÷ÕßÄܹ»Í¨¹ý·þÎñ½Ó¿ÚÀ´»ñµÃδ¾ÊÚȨµÄ·þÎñ½Ó¼û¡£
CVE-2018-18562£º·ìϼûèÊö£ºOSºÅÁî×¢Èë·ì϶£¬·þÎñ½Ó¿ÚÖеIJ»°²È«È¨ÏÞÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£
CVE-2018-18563£º·ìϼûèÊö£ºËÁÒâÎļþ¸²¸Ç·ì϶£¬Èí¼þ¸üлúÔìÖеķì϶ÔÊÐí¹¥»÷Õßͨ¹ý¾«ÐÄÉè¼ÆµÄ¸üаü¸²¸ÇϵͳÉϵÄËÁÒâÎļþ¡£
CVE-2018-18564£º·ìϼûèÊö£ºËÁÒâ´úÂëÖ´Ðзì϶£¬¶Ô·þÎñºÅÁîµÄ²»ÕýÈ·½Ó¼û½ÚÔìÔÊÐí¹¥»÷Õßͨ¹ý¾«ÐÄÔì×÷µÄÐÂÎÅÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
CVE-2018-18565£º·ìϼûèÊö£ºÅäÖÃËÁÒâÅú¸Ä·ì϶£¬²»ÕýÈ·µÄ½Ó¼û½ÚÔìÔÊÐí¹¥»÷Õ߸ü¸ÄÒÇÆ÷ÅäÖá£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP
½¨¸´½¨Òé
ÂÞÊϽ¨Òé´ºÁªÍøÉ豸£¨ÒÔÌ«ÍøºÍWi-Fi£©²ÉÈ¡ÒÔÏ»º½â´ëÊ©£º
ͨ¹ýÆôÓÃÉ豸°²È«Ö°ÄÜ£¬Ï޶ȶÔÉ豸ºÍÏνӵĻù´¡¼Ü¹¹µÄÍøÂçºÍÎïÀí½Ó¼û¡£
±£»¤ÏνӵĶ˵ãÃâÊÜδ¾ÊÚȨµÄ½Ó¼û¡¢ÍµÇԺͶñÒâÈí¼þµÄÇÖº¦¡£
¼à¿ØÏµÍ³ºÍÍøÂç»ù´¡ÉèÊ©ÊÇ·ñ´æÔÚ¿ÉÒɻ£¬²¢Æ¾¾Ý±¾µØÕþ²ßÏòÓйز¿ÃŽøÐл㱨¡£
¶ÔÓÚ·ÇÁªÍøÉ豸£º
Ô¤·Àδ¾ÊÚȨµÄ½Ó¼û¡¢ÍµÇԺͰѳ֡£
¶ÔÓÚËùÓÐÊÜÓ°ÏìµÄ²úÆ·£¬ÂÞÊÏÒÑ´òËãÔÚ2018Äê11ÔÂÆðÍ·°ä²¼ÐµÄÈí¼þ¸üС£
²Î¿¼Á´½Ó
https://ics-cert.us-cert.gov/advisories/ICSMA-18-310-01
https://www.securityfocus.com/bid/105843


¾©¹«Íø°²±¸11010802024551ºÅ