2023-06-13 12:00:33 +00:00
{
"id" : "CVE-2023-30766" ,
"sourceIdentifier" : "vultures@jpcert.or.jp" ,
"published" : "2023-06-13T10:15:10.370" ,
2025-01-06 17:03:46 +00:00
"lastModified" : "2025-01-06T15:15:10.310" ,
2024-12-08 03:06:42 +00:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-06-13 12:00:33 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Hidden functionality issue exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions prior to 91110.1.101106.78, KB-AHR08D versions prior to 91210.1.101106.78, KB-AHR16D versions prior to 91310.1.101106.78, KB-IRIP04A versions prior to 95110.1.100290.78A, KB-IRIP08A versions prior to 95210.1.100290.78A, and KB-IRIP16A versions prior to 95310.1.100290.78A."
}
] ,
2023-06-26 18:00:32 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-06-26 18:00:32 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2025-01-06 17:03:46 +00:00
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-06-26 18:00:32 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:kbdevice:kb-ahr04d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "91110.1.101106.78" ,
"matchCriteriaId" : "E9AD62AA-C479-42EB-B760-6EE8D44DAFAA"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:kbdevice:kb-ahr04d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1863EEE8-C169-4D5B-B933-881DC01DF830"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:kbdevice:kb-ahr08d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "91210.1.101106.78" ,
"matchCriteriaId" : "959EE3B5-CDF0-4E9F-8198-EA2906B2C876"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:kbdevice:kb-ahr08d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "868CB3B3-A09D-4C20-BE79-CCFAC6A64220"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:kbdevice:kb-ahr16d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "91310.1.101106.78" ,
"matchCriteriaId" : "78F9ECB7-F0F7-4823-AC46-D0F39B4873DA"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:kbdevice:kb-ahr16d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "45FD308E-4BCC-4000-B7AB-C30F5758582F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:kbdevice:kb-irip04a_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "95110.1.100290.78a" ,
"matchCriteriaId" : "EA5C6C00-5D77-45FA-9192-11583B287A6F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:kbdevice:kb-irip04a:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0815D725-07A7-4AE0-B342-4443C9D7C186"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:kbdevice:kb-irip08a_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "95210.1.100290.78a" ,
"matchCriteriaId" : "0E6D7D01-09F8-45CB-B0C1-717CE9762AB0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:kbdevice:kb-irip08a:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A9F53B43-1830-479D-AB3D-A4695B2C712D"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:kbdevice:kb-irip16a_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "95310.1.100290.78a" ,
"matchCriteriaId" : "55936F14-6321-4D15-88B5-8D79BF234251"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:kbdevice:kb-irip16a:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "40B44829-A7ED-4AB7-A2FB-0A9142274ADA"
}
]
}
]
}
] ,
2023-06-13 12:00:33 +00:00
"references" : [
{
"url" : "https://jvn.jp/en/vu/JVNVU90812349/" ,
2023-06-26 18:00:32 +00:00
"source" : "vultures@jpcert.or.jp" ,
"tags" : [
"Third Party Advisory"
]
2023-06-13 12:00:33 +00:00
} ,
{
"url" : "https://www.kbdevice.com/news/%e3%83%ac%e3%82%b3%e3%83%bc%e3%83%80%e3%83%bc%e3%81%ae%e3%83%8d%e3%83%83%e3%83%88%e3%83%af%e3%83%bc%e3%82%af%e6%94%bb%e6%92%83%e3%81%ab%e5%af%be%e3%81%99%e3%82%8b%e3%82%a2%e3%83%83%e3%83%97%e3%83%87/" ,
2023-06-26 18:00:32 +00:00
"source" : "vultures@jpcert.or.jp" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://jvn.jp/en/vu/JVNVU90812349/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.kbdevice.com/news/%e3%83%ac%e3%82%b3%e3%83%bc%e3%83%80%e3%83%bc%e3%81%ae%e3%83%8d%e3%83%83%e3%83%88%e3%83%af%e3%83%bc%e3%82%af%e6%94%bb%e6%92%83%e3%81%ab%e5%af%be%e3%81%99%e3%82%8b%e3%82%a2%e3%83%83%e3%83%97%e3%83%87/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
2023-06-13 12:00:33 +00:00
}
]
}