Exposure of Resource to Wrong Sphere in KYOCERA Mobile Print - CVE-2023-25954

 

Exposure of Resource to Wrong Sphere in KYOCERA Mobile Print - CVE-2023-25954

Published: April 12, 2023


Vulnerability identifier: #VU75029
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25954
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the system.

The vulnerability exists due to improper intent handling. A remote attacker can cause a malicious app on the victim's device to send an intent and direct the affected app to download malicious files or apps to the device without notification.


Affected software

KYOCERA Mobile Print
TA/UTAX Mobile Print
Olivetti Mobile Print

How to mitigate CVE-2023-25954

Install updates from vendor's website.

KYOCERA Mobile Print - update to 3.2.0.230227
TA/UTAX Mobile Print - update to 3.2.0.230227
Olivetti Mobile Print - update to 3.2.0.230227

External References

Related Security Bulletins