| [Japanese] | 
| JVNDB-2023-002905 | 
| Multiple vulnerabilities in CBC digital video recorders | 
|
| 
 
Digital video recorders provided by CBC Co.,Ltd. contain multiple vulnerabilities listed below.
 * Improper authentication (CWE-287) - CVE-2023-38585
 * OS command injection (CWE-78) - CVE-2023-40144
 * Hidden functionality (CWE-912) - CVE-2023-40158
 
 Yoshiki Mori, Ushimaru Hayato, Hiromu Kubiura and Masaki Kubo of National Institute of Information and Communications Technology Cybersecurity Research Institute reported these vulnerabilities to JPCERT/CC.
 JPCERT/CC coordinated with the developer.
 
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 8.8 (High) [Other]
 
    Attack Vector: NetworkAttack Complexity: LowPrivileges Required: LowUser Interaction: NoneScope: UnchangedConfidentiality Impact: HighIntegrity Impact: HighAvailability Impact: High 
  
 | 
|
| 
 
	* NR4H, NR8H, NR16H series* DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series
 * NR-4M, NR-8M, NR-16M series
 * NR-4F, NR-8F, NR-16F series
 * DR-16M, DR-8M, DR-4M51 series
 
 | 
| 
 
	CBC Co.,Ltd.
	
		DR-16F42A firmware DR-16F45AT firmware DR-16H firmware DR-16M52 firmware DR-16M52-AV firmware DR-4FX1 firmware DR-4H firmware DR-4M51-AV firmware DR-8F42A firmware DR-8F45AT firmware DR-8H firmware DR-8M52-AV firmware DRH8-4M41-A firmware NR-16F82-16P firmware NR-16F85-8PRA firmware NR-16M firmware NR-4F firmware NR-8F firmware NR16H firmware NR4H firmware NR8-4M71 firmware NR8-8M72 firmware NR8H firmware  | 
| 
 
	
 | 
|
| 
 
An arbitrary OS command may be executed on the device or its settings may be altered by a remote attacker.
 [Comment]
 This analysis assumes a scenario that OS commands are executed on the device using the credentials obtained by exploiting CVE-2023-38585 vulnerability.
 | 
|
| 
 
[Update the firmware]For the following devices, update the firmware to the latest version according to the information provided by the developer.
 
 * NR-4M, NR-8M, NR-16M series
 * NR-4F, NR-8F, NR-16F series
 * DR-16M, DR-8M, DR-4M51 series
 
 [Stop connecting to the internet]
 Since the devices listed below are no longer supported, they do not meet current security requirements. Therefore, it is not suitable for connecting to internet.
 * NR4H, NR8H, NR16H series
 * DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series
 
 For more information, refer to the information provided by the developer.
 | 
|
| 
 
	CBC Co.,Ltd.
	
 | 
|
| 
 
	Improper Authentication(CWE-287) [Other]OS Command Injection(CWE-78) [Other]Hidden Functionality(CWE-912) [Other] | 
|
| 
 
	CVE-2023-38585 CVE-2023-40144 CVE-2023-40158  | 
|
| 
 
	JVN : JVNVU#92545432 National Vulnerability Database (NVD) : CVE-2023-38585 National Vulnerability Database (NVD) : CVE-2023-40144 National Vulnerability Database (NVD) : CVE-2023-40158  | 
|
| 
 
	[2023/08/22]Web page was published
[2024/04/10]References : Contents were added
 
 
 |