JVNVU#98785541
Multiple vulnerabilities in Command Center RX (CCRX) of Kyocera Document Solutions MFPs and printers
Overview
Command Center RX (CCRX), a web interface for MFPs and printers provided by KYOCERA Document Solutions Inc., contains multiple vulnerabilities.
Products Affected
A wide range of products are affected.
For more information, refer to the information provided by the developer.
Description
Command Center RX (CCRX), a web interface for MFPs and printers provided by KYOCERA Document Solutions Inc., contains multiple vulnerabilities listed below.
- Path traversal (CWE-22) - CVE-2023-34259
CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score: 7.5 - Path traversal (CWE-22) - CVE-2023-34260
CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score: 7.5 - Observable response discrepancy (CWE-204) - CVE-2023-34261
CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 5.3
Impact
A remote attacker may obtain sensitive information, or may be able to cause a denial-of-service (DoS) condition on the affected devices.
Solution
Update the firmware
Update the firmware to the latest version according to the information provided by the developer.
For more information, contact your distributor.
Apply the workaround
Deny access from any untrusted peers.
- Connect to a firewall-protected network
- Connect to a network with a private IP address
Vendor Status
Vendor | Link |
KYOCERA Document Solutions Inc. | KYOCERA Command Center RX (CCRX) Security Vulnerability |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Stefan Michlits of SEC Consult reported these vulnerabilities to KYOCERA Document Solutions Inc. and coordinated. KYOCERA Document Solutions Inc. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.