[Japanese]

JVNDB-2022-000004

Label printers "TEPRA" PRO SR5900P / SR-R7900P vulnerable to insufficiently protected credentials

Overview

Label printers "TEPRA" PRO SR5900P / SR-R7900P provided by KING JIM CO.,LTD. contain an insufficiently protected credentials vulnerability (CWE-522).

Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
CVSS V2 Severity:
Base Metrics 3.3 (Low) [IPA Score]
  • Access Vector: Adjacent Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


KING JIM CO.,LTD.
  • Label Printer "Tepra" PRO SR-R7900P Ver.1.030 and earlier
  • Label Printer "Tepra" PRO SR5900P Ver.1.080 and earlier

Impact

An attacker who can access the products via network may obtain credentials to connect to the Wi-Fi access point with the infrastructure mode.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.
The developer has released the following versions that address the vulnerability.

  • Label printer "TEPRA" PRO SR5900P Ver.1.090

  • Label printer "TEPRA" PRO SR-R7900P Ver.1.040


According to the developer, after updating the software to the latest version, it would be unable to change the settings to connect to the Wi-Fi access point or to read the registered information, through the network. Therefore, the developer has released the following software, which removed the function to access the products through the network from the TEPRA Network Config Tool.

  • TEPRA Lable Editor SPC10 for Windows bundling TEPRA Network Config Tool Ver.3.02

  • SMA3 printer driver "TEPRA Driver" for macOS bundling TEPRA Network Config Tool Ver.1.20


The settings can be changed or read via the USB connection as before.
Vendor Information

KING JIM CO.,LTD.
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2022-0184
References

  1. JVN : JVN#81479705
  2. National Vulnerability Database (NVD) : CVE-2022-0184
Revision History

  • [2022/01/13]
      Web page was published