Published:2023/01/12  Last Updated:2023/01/12

JVN#57296685
Multiple vulnerabilities in PIXELA PIX-RT100

Overview

PIX-RT100 provided by PIXELA CORPORATION contains multiple vulnerabilities.

Products Affected

  • PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101

Description

PIX-RT100 provided by PIXELA CORPORATION contains multiple vulnerabilities listed below.

  • OS command injection (CWE-78) - CVE-2023-22304
    CVSS v3 CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score: 8.0
    CVSS v2 AV:A/AC:L/Au:S/C:C/I:C/A:C Base Score: 7.7
  • Backdoor access issue (CWE-912) - CVE-2023-22316
    CVSS v3 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score: 8.8
    CVSS v2 AV:A/AC:L/Au:N/C:C/I:C/A:C Base Score: 8.3

Impact

  • A user who can login to Setting of the product may execute an arbitrary OS command - CVE-2023-22304
  • A network-adjacent attacker may access the product via undocumented Telnet or SSH services - CVE-2023-22316

Solution

Update the Software
Update to the latest version according to the information provided by the developer.
According to the developer, these vulnerabilities have been fixed in version RT100_TEQ_2.1.3_EQ101.

Vendor Status

Vendor Link
PIXELA CORPORATION PIX-RT100 Update (Text in Japanese)

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

MASAHIRO IIDA of LAC Co.,Ltd. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2023-22304
CVE-2023-22316
JVN iPedia JVNDB-2023-000006