Published:2023/07/27  Last Updated:2023/07/27

JVNVU#98785541
Multiple vulnerabilities in Command Center RX (CCRX) of Kyocera Document Solutions MFPs and printers

Overview

Command Center RX (CCRX), a web interface for MFPs and printers provided by KYOCERA Document Solutions Inc., contains multiple vulnerabilities.

Products Affected

A wide range of products are affected.
For more information, refer to the information provided by the developer.

Description

Command Center RX (CCRX), a web interface for MFPs and printers provided by KYOCERA Document Solutions Inc., contains multiple vulnerabilities listed below.

  • Path traversal (CWE-22) - CVE-2023-34259
    CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score: 7.5
  • Path traversal (CWE-22) - CVE-2023-34260
    CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score: 7.5
  • Observable response discrepancy (CWE-204) - CVE-2023-34261
    CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 5.3

Impact

A remote attacker may obtain sensitive information, or may be able to cause a denial-of-service (DoS) condition on the affected devices.

Solution

Update the firmware
Update the firmware to the latest version according to the information provided by the developer.
For more information, contact your distributor.

Apply the workaround
Deny access from any untrusted peers.

  • Connect to a firewall-protected network
  • Connect to a network with a private IP address

Vendor Status

Vendor Link
KYOCERA Document Solutions Inc. KYOCERA Command Center RX (CCRX) Security Vulnerability

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Stefan Michlits of SEC Consult reported these vulnerabilities to KYOCERA Document Solutions Inc. and coordinated. KYOCERA Document Solutions Inc. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia