JVNVU#91077448
SNMP service is enabled by default in Sharp NEC Display Solutions projectors
Overview
Multiple projectors provided by Sharp NEC Display Solutions, Ltd. are configured with SNMP service enabled by default.
Products Affected
- Multiple projectors provided by Sharp NEC Display Solutions, Ltd.
Description
Multiple projectors provided by Sharp NEC Display Solutions, Ltd. are configured with SNMP service enabled by default, therefore can be accessed by specifying SNMP community name "public" (CWE-1242、CVE-2024-7011).
SNMP service configuration (enable/disable) cannot be changed on the management page of the projectors either.
Impact
An attacker may obtain the information of the affected products, and/or conduct a denial-of-service (DoS) attack.
Solution
Update the firmware
Update the firmware to the latest version according to the information provided by the vendor.
Apply the workaround
The vendor recommends that users should apply the workarounds, if the update cannot be applied.
For the details of the updates or workarounds, refer to the information provided by the vendor.
Vendor Status
Vendor | Link |
Sharp NEC Display Solutions, Ltd. | Vulnerabilities in projectors |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
Comment
The analysis assumes the information of the affected products is obtained by an attacker via SNMP service.
Credit
This vulnerability was directly reported to Sharp NEC Display Solutions, Ltd. by the reporter. Sharp NEC Display Solutions, Ltd. reported the case to JPCERT/CC to notify users of the solution through JVN.
Reporter: JP Hofmeyr of Southern Metropolitan Cemeteries Trust