[Japanese]
|
JVNDB-2017-000217
|
Backdoor access issue in Wi-Fi STATION L-02F
|
Wi-Fi STATION L-02F provided by NTT DOCOMO, INC. contains a backdoor access issue.
Japan Computer Emergency Response Team Coordination Center Global Coordination Division Cyber Metrics Line Information Security Analyst Keisuke Shikano reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 9.8 (Critical) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
CVSS V2 Severity: Base Metrics 10.0 (High) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Complete
- Integrity Impact: Complete
- Availability Impact: Complete
|
|
NTT DOCOMO, INC.
- Wi-Fi STATION L-02F Software version V10g and earlier
|
|
An unauthenticated remote attacker may access the device with the administrative privilege and perform an unintended operation.
The reporter has conducted a test and confirmed that an attacker can log in to the device through internet by using an ID and a password, and execute arbitrary command.
|
[Apply an Update]
Apply the update according to the information provided by the provider.
|
NTT DOCOMO, INC.
|
- Permissions(CWE-264) [IPA Evaluation]
|
- CVE-2017-10845
|
- JVN : JVN#68922465
- National Vulnerability Database (NVD) : CVE-2017-10845
- IPA SECURITY ALERTS : Security Alert for Vulnerability in Wi-Fi STATION L-02F (JVN#68922465) (in Japanese)
- JPCERT : JPCERT-AT-2017-0034 (in Japanese)
|
- [2017/09/12]
Web page was published
- [2018/02/28]
References : Content was added
|