3 results (0.003 seconds)

CVSS: 6.1EPSS: 93%CPEs: 2EXPL: 2

11 Jul 2023 — Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575. Las impresoras Kyocera TASKalfa 4053ci hasta 2VG_S000.002.561 permiten /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal para leer archivos arbitrarios en el sistema de archivos, incluso archivos que requieren privilegios de root. NOTA: este problem... • https://packetstorm.news/files/id/173397 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.8EPSS: 2%CPEs: 2EXPL: 2

11 Jul 2023 — Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory. Las impresoras Kyocera TASKalfa 4053ci hasta 2VG_S000.002.561 permiten una denegación de servicio (interrupción del servicio) a través de /wlmdeu%2f%2e%2e%2f%2e%2e seguido de una referencia de directorio como %2fetc%00index.htm para intentar leer el directorio /etc. Kyocera TASKalfa 4... • https://packetstorm.news/files/id/173397 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 2

11 Jul 2023 — Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a "nicht einloggen" error rather than a falsch error. Las impresoras Kyocera TASKalfa 4053ci hasta 2VG_S000.002.561 permiten la identificación de cuentas de usuario válidas mediante la enumeración de nombres de usuario porque conducen a un error "nicht einloggen" en lugar de un error falso. Kyocera TASKalfa 4053ci versions 2VG_S000.002.561 and below suffers from... • https://packetstorm.news/files/id/173397 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •