Trustwave SpiderLabs Security Advisory TWSL2024-001: Authentication Coercion Vulnerability in Kyocera Device Manager Published: 01/08/2024 Version: 1.0 Vendor: KYOCERA Corporation (kyocera.com) Product: Kyocera Device Manager Version affected: Prior to 3.0.1625 Product description: Kyocera Device Manager is a server-based solution and an essential device management tool for mid- to large-sized enterprises, as it drastically simplifies the upkeep of large printer fleets. Kyocera Device Manager allows IT Managers to centrally monitor and administrate large fleets of devices from one remote location. Finding 1: Authentication Coercion via UNC path as Backup Location *****Credit: Jordan Hedges of Trustwave CVE: CVE-2023-50916 CWE: CWE-40 The Kyocera Device Manager administrative application allows administrators to configure the backup location of the database used by the application. Attempting to change this location to a UNC path using the GUI is rejected by the application due to the use of backslashes ("\") as a disallowed path. Intercepting and modifying this request using a web interception proxy or sending the request directly to the application endpoint will allow UNC paths to be set for the backup location. Once the location is updated Kyocera Device Manager attempts to confirm access and will try to authenticate to the UNC path, depending on configuration of the environment this may authenticate to the UNC share specified with Windows NTLM hashes. This could allow NTLM credential relaying or cracking attacks. Proof of Concept (PoC) 1. Authenticate to Kyocera Device Manager. 2. Attempt to modify the backup location and intercept the request to "/backup-restore-service/config/backup-path" using a web proxy such as Burp Suite. 3. Modify the "path" URL parameter to an attacker-controlled UNC path. 4. Submit the request and note the response indicating that Kyocera Device Manager attempted to connect and produced an error. 5. Note on the attacker-controlled host with the target UNC path that a connection has beenmade by the Kyocera Device Manager application. Depending on configuration this may include Windows NTLM hashes. Vendor Response: Accepted and remediated. Remediation Steps: Upgrade to Kyocera Device Manager version 3.1.1213.0. See the Reference section for more information from Kyocera Revision History: 10/11/23 - Vulnerability disclosed to vendor 12/21/23 - Patch released by vendor 01/08/23 - Advisory published References 1. https://www.kyoceradocumentsolutions.us/en/about-us/pr-and-award-certifications/press/kyocera-device-manager-cve-2023-50196-vulnerability-solution-update.html About Trustwave: Trustwave is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Trustwave’s comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes its client’s cyber investment, and improves security resilience. Trusted by thousands of organizations worldwide, Trustwave leverages its world-class team of security consultants, threat hunters, and researchers, and its market-leading security operations platform to decrease the likelihood of attacks and minimize potential impact. Trustwave is an analyst-recognized leader in managed detection and response (MDR), managed security services (MSS), cyber advisory, penetration testing, database security, and email security. The elite Trustwave SpiderLabs team provides industry-defining threat research, intelligence, and threat hunting, all of which are infused into Trustwave services and products to fortify cyber resilience in the age of inevitable cyberattacks. For more information about Trustwave, visit https://www.trustwave.com About Trustwave SpiderLabs: Trustwave SpiderLabs is among the most well-respected teams in the cybersecurity industry, with a reputation for conducting cutting-edge research, plying the foggy corners of the Dark Web for intelligence, proactively protecting clients, and detecting and hunting down threats. With more than 250 specialized experts across the globe, Trustwave SpiderLabs is a world-class team of security consultants, threat hunters, incident responders, forensic investigators, and researchers. For more information about Trustwave SpiderLabs, visit https://www.trustwave.com/spiderlabs Disclaimer: The information provided in this advisory is provided "as is" without warranty of any kind. Trustwave disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Trustwave or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Trustwave or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.