PT-2017-15198 · Panasonic · Panasonic Kx-Hjb1000

Taizoh Tsukamoto

·

Published

2017-10-20

·

Updated

2017-11-07

·

CVE-2017-2133

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000 4.47
Description The issue allows authenticated attackers to execute arbitrary SQL commands. This can be done via unspecified vectors, potentially leading to unauthorized data access or modification.
Recommendations For firmware GHX1YG 14.50, update to a version that fixes this issue. For firmware HJB1000 4.47, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2133

Affected Products

Panasonic Kx-Hjb1000