Lucene search

K
cveJpcertCVE-2017-2149
HistoryApr 28, 2017 - 4:59 p.m.

CVE-2017-2149

2017-04-2816:59:01
CWE-426
jpcert
web.nvd.nist.gov
30
cve-2017-2149
software installer
sdhc
sdxc
memory card
nfc functionality
wireless lan
flashair
transferjet
remote attackers
privileges
vulnerability
security
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.006

Percentile

77.9%

Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Affected configurations

Nvd
Vulners
Node
toshibaflashairRange1.00.03
OR
toshibaflashairRange1.00.04
OR
toshibaflashairRange1.00.06
OR
toshibaflashairRange1.02
OR
toshibaflashairRange2.00.03
OR
toshibaflashairRange3.00.01
OR
toshibaflashairRange3.0.2
VendorProductVersionCPE
toshibaflashair*cpe:2.3:a:toshiba:flashair:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
    "vendor": "Toshiba Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "V1.00.03 and earlier"
      }
    ]
  },
  {
    "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
    "vendor": "Toshiba Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "V3.0.2 and earlier"
      }
    ]
  },
  {
    "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series<W-03>)",
    "vendor": "Toshiba Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "V3.00.01"
      }
    ]
  },
  {
    "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series<W-02>)",
    "vendor": "Toshiba Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "V2.00.03 and earlier"
      }
    ]
  },
  {
    "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
    "vendor": "Toshiba Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "V1.00.04 and earlier"
      }
    ]
  },
  {
    "product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
    "vendor": "Toshiba Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "V1.02 and earlier"
      }
    ]
  },
  {
    "product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
    "vendor": "Toshiba Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "V1.00.06 and earlier"
      }
    ]
  }
]

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.006

Percentile

77.9%

Related for CVE-2017-2149