CVE-2024-27141
Pre-authenticated Time-Based Blind XXE injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request without authentication. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.
Las impresoras Toshiba utilizan comunicación XML para el endpoint API proporcionado por la impresora. Para el endpoint, se utiliza la biblioteca de análisis XML y es vulnerable a una vulnerabilidad de entidad externa XML ciega (XXE) basada en el tiempo. Un atacante puede hacer DoS en las impresoras enviando una solicitud HTTP sin autenticación. Un atacante puede explotar el XXE para recuperar información. En cuanto a los productos/modelos/versiones afectados, consulte la URL de referencia.
103 models of Toshiba Multi-Function Printers (MFP) are vulnerable to 40 different vulnerabilities including remote code execution, local privilege escalation, xml injection, and more.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-02-21 CVE Reserved
- 2024-06-14 CVE Published
- 2024-06-14 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CAPEC
- CAPEC-197: Exponential Data Expansion
References (4)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Toshiba Tec Corporation Search vendor "Toshiba Tec Corporation" | Toshiba Tec E-Studio Multi-function Peripheral (MFP) Search vendor "Toshiba Tec Corporation" for product "Toshiba Tec E-Studio Multi-function Peripheral (MFP)" | * | en |
Affected
|