Published:2024/08/29  Last Updated:2024/08/29

JVNVU#96242582
Multiple vulnerabilities in IDEC Operator Interfaces products

Overview

IDEC Operator Interfaces products contain multiple vulnerabilities which are due to Zuken Elmic TCP/IP protocol stack.

Products Affected

  • HG5G/4G/3G/2G-V Series Operator Interfaces Ver.4.85 and earlier
  • HG4G/3G Series Operator Interfaces Ver.4.85 and earlier
  • HG2G-5F Series Operator Interfaces Ver.4.85 and earlier
  • HG2G-5T Series Operator Interfaces Ver.4.85 and earlier
  • HG1G Series Operator Interfaces Ver.4.85 and earlier
  • HG1P Series Operator Interfaces Ver.4.85 and earlier

Description

IDEC Operator Interfaces products use Zuken Elmic TCP/IP protocol stack, therefore are affected by multiple vulnerabilities listed below which are known as "URGENT/11" and "Ripple20".

CVE-2019-12264, CVE-2020-11901, CVE-2020-11903, CVE-2020-11904, CVE-2020-11906, CVE-2020-11907, CVE-2020-11908, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11914

Impact

An attacker may execute arbitrary code, obtain information, and/or cause a denial of service (DoS) condition.

Solution

Update the System Software
Update the System Software to the latest version according to the information provided by the developer.
The developer has released the following versions that address these vulnerabilities.

  • HG5G/4G/3G/2G-V Series Operator Interfaces Ver.4.86 and later
  • HG4G/3G Series Operator Interfaces Ver.4.86 and later
  • HG2G-5F Series Operator Interfaces Ver.4.86 and later
  • HG2G-5T Series Operator Interfaces Ver.4.86 and later
  • HG1G Series Operator Interfaces Ver.4.86 and later
  • HG1P Series Operator Interfaces Ver.4.86 and later

Vendor Status

References

  1. Japan Vulnerability Notes JVNVU#94736763
    Multiple vulnerabilities in Treck IP protocol stack (Text in Japanese)
  2. Wind River Systems, Inc.
    SECURITY VULNERABILITY RESPONSE INFORMATION TCP/IP Network Stack (IPnet, Urgent/11)
  3. JSOF
    Ripple20

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

IDEC Corporation reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia