« Volver al listado

CVE-2017-2286

Estado: ModificadaAlta (7.8)—

Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for Type B Ver.1.2.1.0 and earlier, SFCard Viewer 2 Ver.2.5.0.0 and earlier, NFC Net Installer Ver.1.1.0.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-2286",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Sony Corporation",
          "product": "NFC Port Software (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S)",
          "versions": [
            {
              "status": "affected",
              "version": "Version 5.5.0.6 and earlier"
            }
          ]
        },
        {
          "vendor": "Sony Corporation",
          "product": "NFC Port Software (for RC-S320, RC-S310/J1C, RC-S310/ED4C)",
          "versions": [
            {
              "status": "affected",
              "version": "Version 5.3.6.7 and earlier"
            }
          ]
        },
        {
          "vendor": "Sony Corporation",
          "product": "PC/SC Activator for Type B",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.2.1.0 and earlier"
            }
          ]
        },
        {
          "vendor": "Sony Corporation",
          "product": "SFCard Viewer 2",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.5.0.0 and earlier"
            }
          ]
        },
        {
          "vendor": "Sony Corporation",
          "product": "NFC Net Installer",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.1.0.0 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-08-02T16:29:00.597",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN16136413/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN16136413/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for Type B Ver.1.2.1.0 and earlier, SFCard Viewer 2 Ver.2.5.0.0 and earlier, NFC Net Installer Ver.1.1.0.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de tipo ruta de búsqueda no confiable permite a los atacantes conseguir privilegios utilizando un archivo DLL troyano en un directorio no especificado. Esta vulnerabilidad afecta a NFC Port Software, versiones 5.5.0.6 y anteriores (para RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S); NFC Port Software, versiones 5.3.6.7 y anteriores (para RC-S320, RC-S310/J1C, RC-S310/ED4C); PC/SC Activator for Type B, versiones 1.2.1.0 y anteriores; SFCard Viewer 2, versiones 2.5.0.0 y anteriores; y NFC Net Installer, versiones 1.1.0.0 y anteriores."
    }
  ],
  "lastModified": "2026-06-17T01:15:53.430",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sony:nfc_port_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58FF206E-61CB-41AE-A055-D17B9D4D3C3F",
              "versionEndIncluding": "5.5.0.6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sony:rc-s310:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "95DFE77A-E624-40C8-BB52-DC1BA2DCFE6D"
            },
            {
              "criteria": "cpe:2.3:h:sony:rc-s320:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4D736000-7095-4F5D-9EFA-3B3CA9D90236"
            },
            {
              "criteria": "cpe:2.3:h:sony:rc-s330:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AC30D968-0F24-41BF-A856-D3A9A9585A6E"
            },
            {
              "criteria": "cpe:2.3:h:sony:rc-s370:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AC4E817B-B58D-4CF2-91EA-79A1C0C275E7"
            },
            {
              "criteria": "cpe:2.3:h:sony:rc-s380:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CB37F739-30F5-416A-9231-1C1F65636A4D"
            },
            {
              "criteria": "cpe:2.3:h:sony:rc-s380\\/s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6F5CB280-9536-4853-BDEE-AEB0EEF5F620"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sony:nfc_port_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C391E1E-E1D8-4C91-A95D-047AAFD7455B",
              "versionEndIncluding": "5.3.6.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sony:rc-s310\\/ed4c:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "187AE859-6A0F-4995-8171-D0464D570B27"
            },
            {
              "criteria": "cpe:2.3:h:sony:rc-s310\\/j1c:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1F74EB26-5AA7-44FA-9B42-1D93929C4F00"
            },
            {
              "criteria": "cpe:2.3:h:sony:rc-s320:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4D736000-7095-4F5D-9EFA-3B3CA9D90236"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sony:pc\\/sc_activator_for_type_b:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F090AA3D-E974-4983-854A-24825A574D81",
              "versionEndIncluding": "1.2.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sony:sfcard_viewer_2:2.5.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F08CDA0-9C53-4991-A5D4-86E9F4B0686B"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sony:nfc_net_installer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7C79B64-38A9-437C-B153-281D4ED8A547",
              "versionEndIncluding": "1.1.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}