Toshiba Printers Vulnerable to Encryption Bypass
CVE-2024-27160
6.2MEDIUM
Key Information:
- Vendor
- Toshiba
- Vendor
- CVE Published:
- 14 June 2024
Summary
All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.
Affected Version(s)
Toshiba Tec e-Studio multi-function peripheral (MFP) Linux see the reference URL
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.