CVE-2024-3497
Directory Traversal Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/models/versions, see the reference URL.
Una vulnerabilidad de path traversal en el servidor web de la impresora Toshiba permite a un atacante sobrescribir archivos originales o agregar otros nuevos a la impresora. En cuanto a los productos/modelos/versiones afectados, consulte la URL de referencia.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Toshiba e-STUDIO2518A printers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the unzip method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of root.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-04-09 CVE Reserved
- 2024-06-14 CVE Published
- 2024-06-14 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-23: Relative Path Traversal
CAPEC
- CAPEC-126: Path Traversal
References (3)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/vu/JVNVU97136265/index.html | ||
https://www.toshibatec.com/information/20240531_01.html | ||
https://www.toshibatec.com/information/pdf/information20240531_01.pdf |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Toshiba Tec Corporation Search vendor "Toshiba Tec Corporation" | Toshiba Tec E-Studio Multi-function Peripheral (MFP) Search vendor "Toshiba Tec Corporation" for product "Toshiba Tec E-Studio Multi-function Peripheral (MFP)" | * | en |
Affected
|