[Japanese]

JVNDB-2017-000090

FlashAir fails to restrict access permissions in PhotoShare

Overview

FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the selected data with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare.

FlashAir fails to restrict access permissions (CWE-425) in PhotoShare.

Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 2.7 (Low) [IPA Score]
  • Access Vector: Adjacent Network
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: None

CVSS V3 Severity:
Base Metrics: 3.5 (Low) [IPA Score]
  • Access Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


TOSHIBA
  • FlashAir SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier
  • FlashAir SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier

For more details, refer to the information provided by the developer.
Impact

A user who access PhotoShare may obtain image data that are set not to be shared with other users.

Because of the vulnerability stated in JVN#81820501, when enabling PhotoShare with web browsers, an attacker with access to the wireless LAN may obtain these image data.
Solution

[Update the software and configure appropriate wireless LAN setting]
Update to the latest software versions of the product using the latest version of FlashAir Software Update tool (V3.00.02 or V2.00.04), and set SSID and password using appropriate application (either for Android or iOS) to prevent unintended accesses.
For more details, refer to the information provided by the developer.
Vendor Information

TOSHIBA
CWE (What is CWE?)

  1. Improper Access Control(CWE-284) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2017-2161
References

  1. JVN : JVN#46372675
Revision History

[2017/05/16]
  Web page was published