Lucene search

K
jvnJapan Vulnerability NotesJVN:56968681
HistoryOct 20, 2022 - 12:00 a.m.

JVN#56968681: Multiple vulnerabilities in nadesiko3

2022-10-2000:00:00
Japan Vulnerability Notes
jvn.jp
35
nadesiko3
os command injection
exceptional conditions
nako3edit
software update
cve-2022-41642
cve-2022-41777
cve-2022-42496

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.0%

Nadesiko3 provided by kujirahand contains multiple vulnerabilities listed below.

OS command injection vulnerability in processing compression and decompression (CWE-78) - CVE-2022-41642

Version Vector Score
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score: 9.8
CVSS v2 AV:N/AC:L/Au:N/C:P/I:P/A:P Base Score: 7.5

Improper check or handling of exceptional conditions in nako3edit (CWE-703) - CVE-2022-41777

Version Vector Score
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Base Score: 5.3
CVSS v2 AV:N/AC:L/Au:N/C:N/I:N/A:P Base Score: 5.0

OS command injection vulnerability via “file” parameter in nako3edit (CWE-78) - CVE-2022-42496

Version Vector Score
CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score: 8.1
CVSS v2 AV:N/AC:M/Au:N/C:P/I:P/A:P Base Score: 6.8

Impact

  • An arbitrary OS command may be executed on the product if compression and/or decompression is executed - CVE-2022-41642
  • Injecting an invalid value to decodeURIComponent of nako3edit may lead the server to crash - CVE-2022-41777
  • An arbitrary OS command may be executed on the product via “file” parameter in nako3edit if appkey of the product is obtained by the remote unauthenticated attacker - CVE-2022-42496

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

Products Affected

CVE-2022-41642

  • Nadesiko3 (PC Version) v3.3.68 and earlier
    CVE-2022-41777, CVE-2022-42496

  • Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.0%