ÂÞÊÏÒ½ÁÆÆ÷е¶à¸ö¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-11-20

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-18561£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 6.5£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18562£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.0£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18563£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.0£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18564£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.3£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-18565£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 8.2£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Accu-Chek Inform II Base Unit / Base Unit Hub¨C03.01.04֮ǰµÄËùÓа汾
Accu-Chek Inform II Instrument¨C03.06.00֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚ14000£©/ 04.03.00֮ǰµÄËùÓа汾£¨ÐòÁкŸßÓÚ14000£©
CoaguChek / cobas h232 Handheld Base Unit¨C03.01.04֮ǰµÄËùÓа汾
CoaguChek Pro II¨C04.03.00֮ǰµÄËùÓа汾
CoaguChek XS Plus¨C03.01.06֮ǰµÄËùÓа汾
CoaguChek XS Pro¨C03.01.06֮ǰµÄËùÓа汾
cobas h 232¨C03.01.03֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚKQ0400000»òKS0400000£©
cobas h 232¨C04.00.04֮ǰµÄËùÓа汾£¨ÐòÁкŵÍÓÚKQ0400000»òKS0400000£©
cobas h 232¨C04.00.04֮ǰµÄËùÓа汾£¨ÐòÁкŸßÓÚKQ0400000»òKS0400000£©


Îó²î¸ÅÊö


ÈðÊ¿¿µ½¡ÊÂÒµ¹«Ë¾ÂÞÊÏ£¨Roche£©Ò½ÁÆÕï¶Ï²¿Ñ§Éú²úµÄ¼¸¿îÒ½ÁÆÆ÷еÖб£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬¿ÉÄÜ»áÈû¼ÕßµÄÈËÉíÇå¾²ÃæÁÙΣº¦¡£¡£¡£
À´×ÔÒÔÉ«ÁÐÒ½ÁÆ×°±¸Çå¾²ÆóÒµMedigateµÄÇå¾²Ñо¿Ô±Niv Yehezkel·¢Ã÷£¬£¬£¬ÓÉÂÞÊÏÉú²úµÄÈý¿îÒ½ÁÆÆ÷е±£´æÎå¸öÇå¾²Îó²î¡£¡£¡£×ܵÄÀ´Ëµ£¬£¬£¬ÕâЩÎó²î»áÓ°Ïìµ½Accu-ChekѪÌÇÒÇ¡¢¿¹ÄýÖÎÁÆÒ½ÁÆ×¨ÒµÖ°Ô±Ê¹ÓõÄCoaguChekÄýѪ¼ì²âÒÇÒÔ¼°Cobas±ãЯʽÊÖ³ÖѪҺÆÊÎöÒÇ¡£¡£¡£
ÔÚÃÀ¹ú¹¤Òµ»¥ÁªÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©×î½üÐû²¼µÄÒ»·Ý×ÉѯÖУ¬£¬£¬ÎÒÃÇ¿ÉÒÔÕÒµ½ËùÓÐÒ×Êܹ¥»÷µÄ²úÆ·ºÍ°æ±¾µÄÏêϸÐÅÏ¢¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬Ã¿Ò»¸öÎó²î¶¼»áÓ°ÏìÂÞÊÏÒ½ÁÆÆ÷еµÄ¶à¸öÐͺźͰ汾¡£¡£¡£
CVE-2018-18561£ºÎó²îÐÎò£ºÈõ»á¼ûƾ֤Îó²î£¬£¬£¬ÔÊÐí¹¥»÷Õß¿ÉÒÔͨ¹ýЧÀͽӿÚÀ´»ñµÃδ¾­ÊÚȨµÄЧÀÍ»á¼û¡£¡£¡£
CVE-2018-18562£ºÎó²îÐÎò£ºOSÏÂÁî×¢ÈëÎó²î£¬£¬£¬Ð§ÀͽӿÚÖеIJ»Ç徲ȨÏÞÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ²Ù×÷ϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
CVE-2018-18563£ºÎó²îÐÎò£ºí§ÒâÎļþÁýÕÖÎó²î£¬£¬£¬Èí¼þ¸üлúÖÆÖеÄÎó²îÔÊÐí¹¥»÷Õßͨ¹ýÈ«ÐÄÉè¼ÆµÄ¸üаüÁýÕÖϵͳÉϵÄí§ÒâÎļþ¡£¡£¡£
CVE-2018-18564£ºÎó²îÐÎò£ºí§Òâ´úÂëÖ´ÐÐÎó²î£¬£¬£¬¶ÔЧÀÍÏÂÁîµÄ²»×¼È·»á¼û¿ØÖÆÔÊÐí¹¥»÷Õßͨ¹ýÈ«ÐÄÖÆ×÷µÄÐÂÎÅÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
CVE-2018-18565£ºÎó²îÐÎò£ºÉèÖÃí§ÒâÐÞ¸ÄÎó²î£¬£¬£¬²»×¼È·µÄ»á¼û¿ØÖÆÔÊÐí¹¥»÷Õ߸ü¸ÄÒÇÆ÷ÉèÖᣡ£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP


ÐÞ¸´½¨Òé


ÂÞÊϽ¨Òé´ºÁªÍø×°±¸£¨ÒÔÌ«ÍøºÍWi-Fi£©½ÓÄÉÒÔÏ»º½â²½·¥£º
ͨ¹ýÆôÓÃ×°±¸Çå¾²¹¦Ð§£¬£¬£¬ÏÞÖÆ¶Ô×°±¸ºÍÅþÁ¬µÄ»ù´¡¼Ü¹¹µÄÍøÂçºÍÎïÆÊÎö¼û¡£¡£¡£
±£»£» £»£»¤ÅþÁ¬µÄ¶ËµãÃâÊÜδ¾­ÊÚȨµÄ»á¼û¡¢ÍµÇԺͶñÒâÈí¼þµÄË𺦡£¡£¡£
¼à¿ØÏµÍ³ºÍÍøÂç»ù´¡ÉèÊ©ÊÇ·ñ±£´æ¿ÉÒɻ£¬£¬£¬²¢Æ¾Ö¤ÍâµØÕþ²ßÏòÏà¹Ø²¿·Ö¾ÙÐб¨¸æ¡£¡£¡£
¹ØÓÚ·ÇÁªÍø×°±¸£º
±ÜÃâδ¾­ÊÚȨµÄ»á¼û¡¢ÍµÇÔºÍʹÓᣡ£¡£
¹ØÓÚËùÓÐÊÜÓ°ÏìµÄ²úÆ·£¬£¬£¬ÂÞÊÏÒÑÍýÏëÔÚ2018Äê11ÔÂ×îÏÈÐû²¼ÐµÄÈí¼þ¸üС£¡£¡£


²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSMA-18-310-01
https://www.securityfocus.com/bid/105843