Published:2023/04/11 Last Updated:2023/04/11
JVNVU#98434809
Multiple mobile printing apps for Android vulnerable to improper intent handling
Overview
Multiple mobile printing apps for Android are vulnerable to improper intent handling.
Products Affected
- Android app "KYOCERA Mobile Print", v3.2.0.230119 and earlier
- Android app "UTAX/TA MobilePrint", v3.2.0.230119 and earlier
- ​Android app "Olivetti Mobile Print", v3.2.0.230119 and earlier
Description
Multiple mobile printing apps for Android are vulnerable to improper intent handling (CWE-668).
Impact
When a malicious app is installed on the victim user's Android device, the app may send an intent and direct the affected app to download malicious files or apps to the device without notification.
Solution
Update the Software
Update the affected app to the latest version according to the information provided by the developer.
Vendor Status
Vendor | Link |
Kyocera Document Solutions | KYOCERA Mobile Print for Android Security Vulnerability |
KYOCERA Mobile Print - Apps on Google Play | |
TA Triumph-Adler GmbH | TA/UTAX Mobile Print - Apps on Google Play |
Olivetti SpA | Olivetti Mobile Print - Apps on Google Play |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
CVSS v3
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score:
5.0
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
Credit
Johan Francsics reported this vulnerability to JPCERT/CC.
JPCERT/CC coordinated with the developer.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2023-25954 |
JVN iPedia |
|