Published:2024/09/27  Last Updated:2024/09/27

JVNVU#91077448
SNMP service is enabled by default in Sharp NEC Display Solutions projectors

Overview

Multiple projectors provided by Sharp NEC Display Solutions, Ltd. are configured with SNMP service enabled by default.

Products Affected

  • Multiple projectors provided by Sharp NEC Display Solutions, Ltd.
As for the details of affected product names, model numbers, and versions, refer to the information provided by the vendor.

Description

Multiple projectors provided by Sharp NEC Display Solutions, Ltd. are configured with SNMP service enabled by default, therefore can be accessed by specifying SNMP community name "public" (CWE-1242CVE-2024-7011).
SNMP service configuration (enable/disable) cannot be changed on the management page of the projectors either.

Impact

An attacker may obtain the information of the affected products, and/or conduct a denial-of-service (DoS) attack.

Solution

Update the firmware
Update the firmware to the latest version according to the information provided by the vendor.

Apply the workaround
The vendor recommends that users should apply the workarounds, if the update cannot be applied.

For the details of the updates or workarounds, refer to the information provided by the vendor.

Vendor Status

Vendor Link
Sharp NEC Display Solutions, Ltd. Vulnerabilities in projectors

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score: 5.3
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)

Comment

The analysis assumes the information of the affected products is obtained by an attacker via SNMP service.

Credit

This vulnerability was directly reported to Sharp NEC Display Solutions, Ltd. by the reporter. Sharp NEC Display Solutions, Ltd. reported the case to JPCERT/CC to notify users of the solution through JVN.
Reporter: JP Hofmeyr of Southern Metropolitan Cemeteries Trust

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia