HP Printers Vulnerable to Remote Code Execution via Web Configuration
CVE-2024-3498
7.8HIGH
Key Information:
- Vendor
- Toshiba
- Vendor
- CVE Published:
- 14 June 2024
Summary
A vulnerability exists within Toshiba Multifunction Printers that allows attackers to exploit certain web-enabled services through the printer's configuration page. By manipulating these services, attackers can successfully execute malicious files and elevate their privileges to root, potentially compromising sensitive data and system integrity. Organizations utilizing affected models should apply security patches and configure their systems to mitigate the risk of unauthorized access.
Affected Version(s)
Toshiba Tec e-Studio multi-function peripheral (MFP) Linux see the reference URL
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We expresses its gratitude to Zhenhua Huang, Harry Zhang and Minmin Li for reporting relevant security vulnerabilities for our products.