[Japanese]

JVNDB-2024-009396

SNMP service is enabled by default in Sharp NEC Display Solutions projectors

Overview

Multiple projectors provided by Sharp NEC Display Solutions, Ltd. are configured with SNMP service enabled by default, therefore can be accessed by specifying SNMP community name "public" (CWE-1242 ,CVE-2024-7011).
SNMP service configuration (enable/disable) cannot be changed on the management page of the projectors either.

This vulnerability was directly reported to Sharp NEC Display Solutions, Ltd. by the reporter. Sharp NEC Display Solutions, Ltd. reported the case to JPCERT/CC to notify users of the solution through JVN.
Reporter: JP Hofmeyr of Southern Metropolitan Cemeteries Trust
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.3 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


Sharp NEC Display Solutions, Ltd.
  • (Multiple Product)

As for the details of affected product names, model numbers, and versions, refer to the information provided by the vendor.
Impact

An attacker may obtain the information of the affected products, and/or conduct a denial-of-service (DoS) attack.

[Comment]
The analysis assumes the information of the affected products is obtained by an attacker via SNMP service.
Solution

[Update the firmware]
Update the firmware to the latest version according to the information provided by the vendor.

[Apply the workaround]
The vendor recommends that users should apply the workarounds, if the update cannot be applied.

For the details of the updates or workarounds, refer to the information provided by the vendor.
Vendor Information

Sharp NEC Display Solutions, Ltd.
CWE (What is CWE?)

  1. Inclusion of Undocumented Features or Chicken Bits(CWE-1242) [Other]
CVE (What is CVE?)

  1. CVE-2024-7011
References

  1. JVN : JVNVU#91077448
Revision History

  • [2024/09/30]
      Web page was published