// For flags

CVE-2017-2149

 

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Vulnerabilidad de ruta de búsqueda no confiable en los instaladores de software: Software Update Tool V1.00.03 y versiones anteriores para tarjetas de memoria SDHC/SDXC con funcionalidad NFC integrada, FlashAir Configuration Software V3.0.2 y versiones anteriores para tarjetas de memoria SDHC con funcionalidad LAN inalámbrica integrada, FlashAir Software Update tool (SD-WE series) V3.00.01 para tarjetas de memoria SDHC con funcionalidad LAN inalámbrica integrada, FlashAir Software Update tool (SD-WD/WC series) V2.00.03 y versiones anteriores para tarjetas de memoria SDHC con funcionalidad LAN inalámbrica integrada, FlashAir Software Update tool (SD-WB/WL series) V1.00.04 y versiones anteriores para tarjetas de memoria SDHC con funcionalidad LAN inalámbrica integrada, Configuration Software V1.02 y versiones anteriores para tarjetas de memoria SDHC con funcionalidad TransferJet integrada, Software Update tool V1.00.06 y versiones anteriores para tarjetas de memoria SDHC con funcionalidad TransferJet integrada, permite a atacantes remotos obtener privilegios a través de una DLL troyanizada en un directorio no especificado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-01 CVE Reserved
  • 2017-04-28 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-426: Untrusted Search Path
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Toshiba
Search vendor "Toshiba"
Flashair
Search vendor "Toshiba" for product "Flashair"
<= 1.00.03
Search vendor "Toshiba" for product "Flashair" and version " <= 1.00.03"
-
Affected
Toshiba
Search vendor "Toshiba"
Flashair
Search vendor "Toshiba" for product "Flashair"
<= 1.00.04
Search vendor "Toshiba" for product "Flashair" and version " <= 1.00.04"
-
Affected
Toshiba
Search vendor "Toshiba"
Flashair
Search vendor "Toshiba" for product "Flashair"
<= 1.00.06
Search vendor "Toshiba" for product "Flashair" and version " <= 1.00.06"
-
Affected
Toshiba
Search vendor "Toshiba"
Flashair
Search vendor "Toshiba" for product "Flashair"
<= 1.02
Search vendor "Toshiba" for product "Flashair" and version " <= 1.02"
-
Affected
Toshiba
Search vendor "Toshiba"
Flashair
Search vendor "Toshiba" for product "Flashair"
<= 2.00.03
Search vendor "Toshiba" for product "Flashair" and version " <= 2.00.03"
-
Affected
Toshiba
Search vendor "Toshiba"
Flashair
Search vendor "Toshiba" for product "Flashair"
<= 3.00.01
Search vendor "Toshiba" for product "Flashair" and version " <= 3.00.01"
-
Affected
Toshiba
Search vendor "Toshiba"
Flashair
Search vendor "Toshiba" for product "Flashair"
<= 3.0.2
Search vendor "Toshiba" for product "Flashair" and version " <= 3.0.2"
-
Affected