Lucene search

K
jvnJapan Vulnerability NotesJVN:69967692
HistoryAug 29, 2018 - 12:00 a.m.

JVN#69967692: Multiple script injection vulnerabilities in multiple Yamaha network devices

2018-08-2900:00:00
Japan Vulnerability Notes
jvn.jp
518

5.2 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:P/I:P/A:P

6.8 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.3%

The management screen of multiple network devices provided by Yamaha Corporation contains multiple script injection vulnerabilities (CWE-74).

Impact

In the case where multiple administrators manage an affected device, an administrator with malicious intent may embed an arbitrary script into the management screen. The embedded script may be executed when another administrator logs into the screen.

Solution

Update the Firmware
Apply the firmware update according to the information provided by the developer.

Products Affected

  • Yamaha Broadband VoIP Router RT57i Rev.8.00.95 and earlier
  • Yamaha Broadband VoIP Router RT58i Rev.9.01.51 and earlier
  • Yamaha Broadband VoIP Router NVR500 Rev.11.00.36 and earlier
  • Yamaha Gigabit VPN Router RTX810 Rev.11.01.31 and earlier
  • Yamaha Firewall FWX120 Rev.11.03.25 and earlier

5.2 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:P/I:P/A:P

6.8 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.3%

Related for JVN:69967692