[Japanese]
|
JVNDB-2023-002725
|
Multiple vulnerabilities in Command Center RX (CCRX) of Kyocera Document Solutions MFPs and printers
|
Command Center RX (CCRX), a web interface for MFPs and printers provided by KYOCERA Document Solutions Inc., contains multiple vulnerabilities listed below.
* Path traversal (CWE-22) - CVE-2023-34259
* Path traversal (CWE-22) - CVE-2023-34260
* Observable response discrepancy (CWE-204) - CVE-2023-34261
Stefan Michlits of SEC Consult reported these vulnerabilities to KYOCERA Document Solutions Inc. and coordinated.
KYOCERA Document Solutions Inc. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.
|
CVSS V3 Severity: Base Metrics 7.5 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2023-34260
|
CVSS V3 Severity:
Base Metrics:7.5 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-34259
|
CVSS V3 Severity:
Base Metrics:5.3 (Medium) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-34261
|
A wide range of products are affected. For more information, refer tothe information provided by the developer.
|
KYOCERA Document Solutions
|
|
A remote attacker may obtain sensitive information, or may be able to cause a denial-of-service (DoS) condition on the affected devices.
|
[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
For more information, contact your distributor.
[Apply the workaround]
Deny access from any untrusted peers.
* Connect to a firewall-protected network
* Connect to a network with a private IP address
|
KYOCERA Document Solutions
|
- Response Discrepancy Information Exposure(CWE-204) [Other]
- Path Traversal(CWE-22) [Other]
|
- CVE-2023-34259
- CVE-2023-34260
- CVE-2023-34261
|
- JVN : JVNVU#98785541
- National Vulnerability Database (NVD) : CVE-2023-34259
- National Vulnerability Database (NVD) : CVE-2023-34260
- National Vulnerability Database (NVD) : CVE-2023-34261
|
- [2023/07/28]
Web page was published
- [2024/05/07]
References : Contents were added
|