CVE-2023-25954
KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling.
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the victim user's Android device, the app may send an intent and direct the affected app to download malicious files or apps to the device without notification.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668
- Affected
- kyocera/mobile print · triumph-adler/mobile print · olivetti/mobile print
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/vu/JVNVU98434809/Third Party Advisory
- https://play.google.com/store/apps/details?id=com.kyocera.kyoprintProduct
- https://play.google.com/store/apps/details?id=com.kyocera.kyoprintolivettiProduct
- https://play.google.com/store/apps/details?id=com.kyocera.kyoprinttautaxProduct
- https://www.kyoceradocumentsolutions.com/en/our-business/security/information/2023-04-11.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU98434809/Third Party Advisory
- https://play.google.com/store/apps/details?id=com.kyocera.kyoprintProduct
- https://play.google.com/store/apps/details?id=com.kyocera.kyoprintolivettiProduct
- https://play.google.com/store/apps/details?id=com.kyocera.kyoprinttautaxProduct
- https://www.kyoceradocumentsolutions.com/en/our-business/security/information/2023-04-11.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.