Exposure of Resource to Wrong Sphere in KYOCERA Mobile Print - CVE-2023-25954
Published: April 12, 2023
Vulnerability identifier: #VU75029
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25954
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the system.
The vulnerability exists due to improper intent handling. A remote attacker can cause a malicious app on the victim's device to send an intent and direct the affected app to download malicious files or apps to the device without notification.
Affected software
KYOCERA Mobile Print
TA/UTAX Mobile Print
Olivetti Mobile Print
TA/UTAX Mobile Print
Olivetti Mobile Print
How to mitigate CVE-2023-25954
Install updates from vendor's website.
KYOCERA Mobile Print - update to 3.2.0.230227
TA/UTAX Mobile Print - update to 3.2.0.230227
Olivetti Mobile Print - update to 3.2.0.230227
TA/UTAX Mobile Print - update to 3.2.0.230227
Olivetti Mobile Print - update to 3.2.0.230227