« Back to list

CVE-2017-10890

Status: ModifiedMedium (4.6)—

Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform arbitrary operations or access information via unspecified vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (5)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-10890",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.6,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Sharp Corporation",
          "product": "RX-V200 firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 09.87.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-V100 firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 03.29.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-CLV1-P firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 79.17.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-CLV2-B firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 89.07.17.09"
            }
          ]
        },
        {
          "vendor": "Sharp Corporation",
          "product": "RX-CLV3-N firmware",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 91.09.17.10"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-17T14:29:00.403",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN76382932/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN76382932/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-384"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform arbitrary operations or access information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Un error de gestión de sesiones en RX-V200 con versiones de firmware anteriores a la 09.87.17.09, RX-V100 con versiones de firmware anteriores a la 03.29.17.09, RX-CLV1-P con versiones de firmware anteriores a la 79.17.17.09, RX-CLV2-B con versiones de firmware anteriores a la 89.07.17.09 y RX-CLV3-N con versiones de firmware anteriores a la 91.09.17.10 permite que un atacante en la misma red LAN realice operaciones arbitrarias o acceda a información mediante vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T01:00:52.130",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-v200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F93BE0D7-93F2-416A-95D2-5572ABDA476E",
              "versionEndExcluding": "09.87.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-v200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "213C19FE-D159-402C-A07C-AE9F5A9B6F1F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-v100_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4FAD03A-268C-4F47-93FC-00D37556C290",
              "versionEndExcluding": "03.29.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-v100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B86C4910-D1AC-4052-A058-08944AD251C0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-clv1-p_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65CD9A51-48D4-4668-9260-129F03EDF01F",
              "versionEndExcluding": "79.17.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-clv1-p:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "018AA4E8-9986-4C45-8181-01AA43C81077"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-clv2-b_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C528EF4-E644-4357-8A14-B39527FFB21C",
              "versionEndExcluding": "89.07.17.09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-clv2-b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "39D3526B-D7D8-4D0C-AA1D-85566A3C442A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sharp:rx-clv3-n_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEA165C4-40B8-4681-ADF5-C2B020299B83",
              "versionEndExcluding": "91.09.17.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sharp:rx-clv3-n:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "21766F38-1FF6-45FA-BE4F-04DD132DD3A8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}