Toshiba Printers Vulnerable to Email Attack via Insecure Sendmail Configuration
CVE-2024-27167

7.4HIGH

Key Information:

Vendor
Toshiba
Vendor
CVE Published:
14 June 2024

Summary

Toshiba printers utilize Sendmail for email functionality, and this implementation is compromised due to the presence of insecure directories. A local attacker can exploit this vulnerability by injecting a malicious Sendmail configuration file, leading to unauthorized changes in email settings. This vulnerability poses risks for various models and versions of Toshiba printers, making it critical for users to review their security configurations to mitigate potential exploitation.

Affected Version(s)

Toshiba Tec e-Studio multi-function peripheral (MFP) Linux see the reference URL

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.
.