[Japanese]

JVNDB-2022-001477

Netcommunity OG410X and OG810X VoIP gateway/Hikari VoIP adapter for business offices vulnerable to OS command injection

Overview

Netcommunity OG410X and OG810X series provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION and NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION contain an OS command injection vulnerability (CWE-78, CVE-2022-22986).

Chuya Hayakawa of 00One, Inc. reported this vulnerability to NTT East and NTT West and coordinated. NTT East, NTT West and JPCERT/CC published respective advisories in order to notify users of this vulnerability.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 8.0 (High) [Other]
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS V2 Severity:
Base Metrics 8.3 (High) [NVD Score]
  • Access Vector: Adjacent Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: Complete
  • Integrity Impact: Complete
  • Availability Impact: Complete
Affected Products


NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION
  • Netcommunity OG410Xa firmware Ver.2.28 and earlier
  • Netcommunity OG410Xi firmware Ver.2.28 and earlier
  • Netcommunity OG810Xa firmware Ver.2.28 and earlier
  • Netcommunity OG810Xi firmware Ver.2.28 and earlier
NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION
  • Netcommunity OG410Xa firmware Ver.2.28 and earlier
  • Netcommunity OG410Xi firmware Ver.2.28 and earlier
  • Netcommunity OG810Xa firmware Ver.2.28 and earlier
  • Netcommunity OG810Xi firmware Ver.2.28 and earlier

Impact

An arbitrary OS command may be executed by an attacker via specially crafted config files.
Solution

[Update the firmware]
Apply the appropriate firmware update according to the information provided by the developer.
Vendor Information

NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION
CWE (What is CWE?)

  1. OS Command Injection(CWE-78) [Other]
CVE (What is CVE?)

  1. CVE-2022-22986
References

  1. JVN : JVNVU#94900322
  2. National Vulnerability Database (NVD) : CVE-2022-22986
Revision History

  • [2022/03/23]
      Web page was published