Toshiba Printers Vulnerable to Email Attack via Insecure Sendmail Configuration
CVE-2024-27167
7.4HIGH
Key Information:
- Vendor
- Toshiba
- Vendor
- CVE Published:
- 14 June 2024
Summary
Toshiba printers utilize Sendmail for email functionality, and this implementation is compromised due to the presence of insecure directories. A local attacker can exploit this vulnerability by injecting a malicious Sendmail configuration file, leading to unauthorized changes in email settings. This vulnerability poses risks for various models and versions of Toshiba printers, making it critical for users to review their security configurations to mitigate potential exploitation.
Affected Version(s)
Toshiba Tec e-Studio multi-function peripheral (MFP) Linux see the reference URL
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.