[Japanese]
|
JVNDB-2022-002768
|
Multiple vulnerabilities in UNIMO Technology digital video recorders
|
Multiple digital video recorders provided by UNIMO Technology Co., Ltd contain multiple vulnerabilities listed below.
* Improper Authentication (CWE-287) - CVE-2022-44620
* OS Command Injection (CWE-78) - CVE-2022-44606
* Hidden Functionality (CWE-912) - CVE-2022-43464
The reporter states that attacks exploiting these vulnerabilities have been observed.
Yoshiki Mori, Ushimaru Hayato, Hiromu Kubiura and Masaki Kubo of National Institute of Information and Communications Technology Cybersecurity Research Institute reported these vulnerabilities to the developer and coordinated. After coordination was completed, this case was reported to JPCERT/CC and JPCERT/CC coordinated with the developer for the publication.
|
CVSS V3 Severity: Base Metrics 8.8 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
|
|
UNIMO Technology Co., Ltd
- UDR-JA1604 firmware versions 71x10.1.107112.43A and earlier
- UDR-JA1608 firmware versions 71x10.1.107112.43A and earlier
- UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier
|
|
An arbitrary OS command may be executed on the product or the device settings may be altered.
This analysis assumes a scenario that OS commands are executed on the device using the authentication information obtained by CVE-2022-44620.
|
[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
This vulnerability has been addressed in the firmware version 71x10.1.107114.43A.
|
UNIMO Technology Co., Ltd
|
- Improper Authentication(CWE-287) [Other]
- OS Command Injection(CWE-78) [Other]
- Hidden Functionality(CWE-912) [Other]
|
- CVE-2022-44620
- CVE-2022-44606
- CVE-2022-43464
|
- JVN : JVNVU#94514762
- National Vulnerability Database (NVD) : CVE-2022-43464
- National Vulnerability Database (NVD) : CVE-2022-44606
- National Vulnerability Database (NVD) : CVE-2022-44620
|
- [2022/12/02]
Web page was published
- [2024/06/03]
References : Contents were added
|