JVN#87164507
Calsos CSDJ fails to restrict access permissions
Overview
Calsos CSDJ provided by NEC Platforms, Ltd. fails to restrict access permissions.
Products Affected
- CSDJ-B 01.08.00 and earlier
- CSDJ-H 01.08.00 and earlier
- CSDJ-D 01.08.00 and earlier
- CSDJ-A 03.08.00 and earlier
Description
Calsos CSDJ provided by NEC Platforms, Ltd. fails to restrict access permissions (CWE-264), which may lead to an unauthorized user being able to view the historical data without access privileges.
Impact
A user who can login to the product may obtain unauthorized historical data without access privileges.
Solution
Apply the appropriate firmware update
Apply the appropriate firimware update according to the information provided by the developer.
Apply a Workaround
The following workaround may mitigate the impacts of this vulnerability.
- Restrict the user permission to view all histrical data (i.e. "Login histry", "Operation history", "Control history", and "Report history")
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
Access Vector(AV) | Local (L) | Adjacent Network (A) | Network (N) |
---|---|---|---|
Access Complexity(AC) | High (H) | Medium (M) | Low (L) |
Authentication(Au) | Multiple (M) | Single (S) | None (N) |
Confidentiality Impact(C) | None (N) | Partial (P) | Complete (C) |
Integrity Impact(I) | None (N) | Partial (P) | Complete (C) |
Availability Impact(A) | None (N) | Partial (P) | Complete (C) |
Credit
Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2021-20653 |
JVN iPedia |
JVNDB-2021-000014 |