Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, CoaguChek XS Plus before 03.01.06, CoaguChek XS Pro before 03.01.06, cobas h 232 before 03.01.03 (Serial Number below KQ0400000 or KS0400000) and cobas h 232 before 04.00.04 (Serial Number above KQ0400000 or KS0400000). Improper access control to a service command allows attackers in the adjacent network to execute arbitrary code on the system through a crafted Poct1-A message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款Roche设备代码问题漏洞
Vulnerability Description
Roche Accu-Chek Inform II Instrument等都是瑞士Roche公司的产品。Accu-Chek Inform II Instrument是一款用于葡萄糖测试和监测的手持式设备。CoaguChek Pro II是一款用于凝血功能检测的设备。cobas h 232是一款心血管疾病分析设备。 多款Roche设备的软件更新机制中存在代码问题漏洞,该漏洞源于程序没有进行正确的访问控制。攻击者可借助特制的更新包利用该漏洞写入任意文件。以下设备和版本受到影响:Accu-Chek Inform
CVSS Information
N/A
Vulnerability Type
N/A