[Japanese]

JVNDB-2022-002768

Multiple vulnerabilities in UNIMO Technology digital video recorders

Overview

Multiple digital video recorders provided by UNIMO Technology Co., Ltd contain multiple vulnerabilities listed below.

* Improper Authentication (CWE-287) - CVE-2022-44620
* OS Command Injection (CWE-78) - CVE-2022-44606
* Hidden Functionality (CWE-912) - CVE-2022-43464

The reporter states that attacks exploiting these vulnerabilities have been observed.

Yoshiki Mori, Ushimaru Hayato, Hiromu Kubiura and Masaki Kubo of National Institute of Information and Communications Technology Cybersecurity Research Institute reported these vulnerabilities to the developer and coordinated. After coordination was completed, this case was reported to JPCERT/CC and JPCERT/CC coordinated with the developer for the publication.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 8.8 (High) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
Affected Products


UNIMO Technology Co., Ltd
  • UDR-JA1604 firmware versions 71x10.1.107112.43A and earlier
  • UDR-JA1608 firmware versions 71x10.1.107112.43A and earlier
  • UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier

Impact

An arbitrary OS command may be executed on the product or the device settings may be altered.

This analysis assumes a scenario that OS commands are executed on the device using the authentication information obtained by CVE-2022-44620.
Solution

[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
This vulnerability has been addressed in the firmware version 71x10.1.107114.43A.
Vendor Information

UNIMO Technology Co., Ltd
CWE (What is CWE?)

  1. Improper Authentication(CWE-287) [Other]
  2. OS Command Injection(CWE-78) [Other]
  3. Hidden Functionality(CWE-912) [Other]
CVE (What is CVE?)

  1. CVE-2022-44620
  2. CVE-2022-44606
  3. CVE-2022-43464
References

  1. JVN : JVNVU#94514762
Revision History

  • [2022/12/02]
      Web page was published