// For flags

CVE-2024-36251

Sharp Multi-Function Printer 18 Vulnerabilities

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

La interfaz web de los dispositivos afectados procesa incorrectamente algunas solicitudes HTTP manipuladas, lo que provoca un bloqueo del dispositivo. Más precisamente, un parámetro manipulado para billcodedef_sub_sel.html no se procesa correctamente y se produce un bloqueo del dispositivo. En cuanto a los detalles de los nombres de los productos afectados, los números de modelo y las versiones, consulte la información proporcionada por los respectivos proveedores que se enumeran en [Referencias].

308 different models of Sharp Multi-Function Printers (MFP) are vulnerable to 18 different vulnerabilities including remote code execution, local file inclusion, credential disclosure, and more.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
Poc
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-05-22 CVE Reserved
  • 2024-07-04 CVE Published
  • 2024-07-04 First Exploit
  • 2024-11-26 CVE Updated
  • 2024-11-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-125: Out-of-bounds Read
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sharp
Search vendor "Sharp"
Bp-b537wr
Search vendor "Sharp" for product "Bp-b537wr"
*-
Affected
Sharp
Search vendor "Sharp"
Bp-b540wr
Search vendor "Sharp" for product "Bp-b540wr"
*-
Affected
Sharp
Search vendor "Sharp"
Bp-b547wd
Search vendor "Sharp" for product "Bp-b547wd"
*-
Affected
Sharp
Search vendor "Sharp"
Bp-b550wd
Search vendor "Sharp" for product "Bp-b550wd"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-b355w
Search vendor "Sharp" for product "Mx-b355w"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-b355wt
Search vendor "Sharp" for product "Mx-b355wt"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-b355wz
Search vendor "Sharp" for product "Mx-b355wz"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-b455w
Search vendor "Sharp" for product "Mx-b455w"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-b455wt
Search vendor "Sharp" for product "Mx-b455wt"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-b455wz
Search vendor "Sharp" for product "Mx-b455wz"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m2630
Search vendor "Sharp" for product "Mx-m2630"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m3050
Search vendor "Sharp" for product "Mx-m3050"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m3070
Search vendor "Sharp" for product "Mx-m3070"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m3550
Search vendor "Sharp" for product "Mx-m3550"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m3570
Search vendor "Sharp" for product "Mx-m3570"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m4050
Search vendor "Sharp" for product "Mx-m4050"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m4070
Search vendor "Sharp" for product "Mx-m4070"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m5050
Search vendor "Sharp" for product "Mx-m5050"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m5070
Search vendor "Sharp" for product "Mx-m5070"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m6050
Search vendor "Sharp" for product "Mx-m6050"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m6070
Search vendor "Sharp" for product "Mx-m6070"
*-
Affected
Sharp
Search vendor "Sharp"
Mx-m905
Search vendor "Sharp" for product "Mx-m905"
*-
Affected