[Japanese]

JVNDB-2018-000081

Multiple vulnerabilities in ORCA(Online Receipt Computer Advantage)

Overview

ORCA(Online Receipt Computer Advantage) provided by ORCA Management Organization Co., Ltd contains vulnerabilities listed below.
* OS command injection (CWE-78) - CVE-2018-0643
* Buffer overflow (CWE-119) - CVE-2018-0644

IoT x Security Hackathon 2016 all participants reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.5 (Medium) [IPA Score]
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: Low
CVSS V2 Severity:
Base Metrics 5.2 (Medium) [IPA Score]
  • Access Vector: Adjacent Network
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2018-0644


CVSS V3 Severity:
Base Metrics: 4.1 (Medium) [IPA Score]
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: Low
CVSS V2 Severity:
Base Metrics: 4.9 (Medium) [IPA Score]
  • Access Vector: Adjacent Network
  • Access Complexity: Medium
  • Authentication: Single
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2018-0643
Affected Products


ORCA Management Organization Co., Ltd
  • Ubuntu14.04 ORCA(Online Receipt Computer Advantage) 4.8.0(panda-server) 1:1.4.9+p41-u4jma1 and earlier (CVE-2018-0643)
  • Ubuntu14.04 ORCA(Online Receipt Computer Advantage) 4.8.0(panda-client2) 1:1.4.9+p41-u4jma1 and earlier (CVE-2018-0644)
  • Ubuntu14.04 ORCA(Online Receipt Computer Advantage) 5.0.0(panda-client2) 1:2.0.0+p48-u4jma1 and earlier (CVE-2018-0644)
  • Ubuntu16.04 ORCA(Online Receipt Computer Advantage) 5.0.0(panda-client2) 1:2.0.0+p48-u5jma1 and earlier (CVE-2018-0644)

Impact

The possible impact of each vulnerability is as follows:

* A user with access to the network that is connected to the affected product may execute an arbitrary command on the product - CVE-2018-0643
* If a user opens a specially crafted file while logged into the affected product, that may result in a denial-of-service (DoS) condition - CVE-2018-0644
Solution

[Update the software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

ORCA Management Organization Co., Ltd
CWE (What is CWE?)

  1. Buffer Errors(CWE-119) [IPA Evaluation]
  2. OS Command Injection(CWE-78) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2018-0643
  2. CVE-2018-0644
References

  1. JVN : JVN#37376131
  2. National Vulnerability Database (NVD) : CVE-2018-0643
  3. National Vulnerability Database (NVD) : CVE-2018-0644
Revision History

  • [2018/07/18]
      Web page was published
  • [2019/07/25]
      References : Contents were added