Hardcoded Keys Expose Administrative Interfaces to Attack
CVE-2024-27168
7.1HIGH
Key Information:
- Vendor
- Toshiba
- Vendor
- CVE Published:
- 14 June 2024
Summary
The authentication mechanism in certain Toshiba TEC products uses hardcoded keys for access to internal APIs. This security design flaw can potentially allow an attacker to bypass authentication controls simply by exploiting knowledge of these private keys. As a result, unauthorized individuals may gain access to sensitive administrative interfaces, posing significant risks to the integrity and confidentiality of the affected systems. Organizations using these products are advised to review their security measures and implement alternative authentication strategies to mitigate the risk.
Affected Version(s)
Toshiba Tec e-Studio multi-function peripheral (MFP) Linux see the reference URL
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.