Published:2023/09/26  Last Updated:2023/09/26

JVNVU#95549489
Multiple vulnerabilities in Panasonic KW Watcher

Overview

KW Watcher provided by Panasonic contains multiple vulnerabilities.

Products Affected

  • KW Watcher Ver.1.00 to Ver.2.82

Description

KW Watcher provided by Panasonic contains multiple vulnerabilities listed below.

  • Improper restriction of operations within the bounds of a memory buffer (CWE-119) - CVE-2023-3471
    CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Base Score: 8.6
  • Use after free (CWE-416) - CVE-2023-3472
    CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Base Score: 8.6

Impact

If a user opens a specially crafted configuration file created by an attacker, arbitrary code may be executed.

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Michael Heinzl reported these vulnerabilities to Panasonic and coordinated.
After the coordination was completed, Panasonic reported the case to JPCERT/CC to notify users of the solutions through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia