Published:2013/10/18  Last Updated:2013/10/18

JVN#52509236
HDL-A and HDL2-A Series vulnerable in session management

Overview

HDL-A and HDL2-A Series provided by I-O DATA DEVICE, INC. contain a vulnerability related to the management of sessions.

Products Affected

  • HDL-A Series (includes HDL-AS, HDL-AH, HDL-A/E Series) firmware version 1.07 and earlier
  • HDL2-A Series (includes HDL2-AH, HDL2-A/E Series) firmware version 1.07 and earlier

Description

HDL-A and HDL2-A Series provided by I-O DATA DEVICE, INC. are LAN connectable hard disk drives. HDL-A and HDL2-A Series contain a vulnerability related to the management of sessions.

Impact

A remote unauthenticated attacker may impersonate a user. As a result, information may be disclosed or altered.

Solution

Update the Firmware
Apply the firmware update provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
I-O DATA DEVICE, INC. vulnerable 2013/10/18 I-O DATA DEVICE, INC. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Analyzed on 2013.10.18

Measures Conditions Severity
Access Required can be attacked over the Internet using packets
  • High
Authentication anonymous or no authentication (IP addresses do not count)
  • High
User Interaction Required the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file
  • Mid
Exploit Complexity some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls)
  • Mid-High

Description of each analysis measures

Credit

Kazuki Hirota of Keio University Keiji Takeda Research Group reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2013-4712
JVN iPedia JVNDB-2013-000095