Lucene search

K
jvnJapan Vulnerability NotesJVN:21636825
HistoryJul 05, 2021 - 12:00 a.m.

JVN#21636825: A-Stage SCT-40CM01SR and AT-40CM01SR vulnerable to authentication bypass

2021-07-0500:00:00
Japan Vulnerability Notes
jvn.jp
63
a-stage inc
televisions
authentication bypass
cwe-287
telnet
firmware update
repair support

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.6%

SCT-40CM01SR and AT-40CM01SR provided by A-Stage Inc. are liquid crystal televisions. SCT-40CM01SR and AT-40CM01SR contain an authentication bypass vulnerability (CWE-287).

Impact

An attacker who can access the device may log in via telnet without authentication and execute an arbitrary command.

According to the developer, even if an arbitrary command is executed, programs regarding the functions of the products can not be altered or deleted.

Solution

Update the firmware
Update the firmware to the latest version according to the information provided by the developer.
According to the developer, the update requires a repair support by the developer. For more information, contact the developer.

Products Affected

  • SCT-40CM01SR and AT-40CM01SR

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.6%

Related for JVN:21636825