« Volver al listado

CVE-2017-10890

Estado: ModificadaMedia (4.6)—

Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform arbitrary operations or access information via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-10890",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.6,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Sharp Corporation",
          "product": "RX-V200 firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 09.87.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-V100 firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 03.29.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-CLV1-P firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 79.17.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-CLV2-B firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 89.07.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-CLV3-N firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 91.09.17.10"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-17T14:29:00.403",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN76382932/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN76382932/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-384"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform arbitrary operations or access information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Un error de gestión de sesiones en RX-V200 con versiones de firmware anteriores a la 09.87.17.09, RX-V100 con versiones de firmware anteriores a la 03.29.17.09, RX-CLV1-P con versiones de firmware anteriores a la 79.17.17.09, RX-CLV2-B con versiones de firmware anteriores a la 89.07.17.09 y RX-CLV3-N con versiones de firmware anteriores a la 91.09.17.10 permite que un atacante en la misma red LAN realice operaciones arbitrarias o acceda a información mediante vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T01:00:52.130",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-v200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F93BE0D7-93F2-416A-95D2-5572ABDA476E",
              "versionEndExcluding": "09.87.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-v200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "213C19FE-D159-402C-A07C-AE9F5A9B6F1F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-v100_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4FAD03A-268C-4F47-93FC-00D37556C290",
              "versionEndExcluding": "03.29.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-v100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B86C4910-D1AC-4052-A058-08944AD251C0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-clv1-p_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65CD9A51-48D4-4668-9260-129F03EDF01F",
              "versionEndExcluding": "79.17.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-clv1-p:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "018AA4E8-9986-4C45-8181-01AA43C81077"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-clv2-b_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C528EF4-E644-4357-8A14-B39527FFB21C",
              "versionEndExcluding": "89.07.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-clv2-b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "39D3526B-D7D8-4D0C-AA1D-85566A3C442A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-clv3-n_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEA165C4-40B8-4681-ADF5-C2B020299B83",
              "versionEndExcluding": "91.09.17.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-clv3-n:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "21766F38-1FF6-45FA-BE4F-04DD132DD3A8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}