CVE-2024-3498
Incorrect Permission Assignment Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.
Luego, los atacantes pueden ejecutar archivos maliciosos habilitando ciertos servicios de la impresora a través de la página de configuración web y elevando sus privilegios a root. En cuanto a los productos/modelos/versiones afectados, consulte la URL de referencia.
This vulnerability allows local attackers to execute arbitrary code on affected installations of Toshiba e-STUDIO2518A printers. Authentication is required to exploit this vulnerability.
The specific flaw exists within the vsftpd daemon. The issue results from incorrect permissions set on folders. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-04-09 CVE Reserved
- 2024-06-14 CVE Published
- 2024-06-14 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-250: Execution with Unnecessary Privileges
CAPEC
- CAPEC-233: Privilege Escalation
References (3)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/vu/JVNVU97136265/index.html | ||
https://www.toshibatec.com/information/20240531_01.html | ||
https://www.toshibatec.com/information/pdf/information20240531_01.pdf |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Toshiba Tec Corporation Search vendor "Toshiba Tec Corporation" | Toshiba Tec E-Studio Multi-function Peripheral (MFP) Search vendor "Toshiba Tec Corporation" for product "Toshiba Tec E-Studio Multi-function Peripheral (MFP)" | * | en |
Affected
|