Action not permitted
Modal body text goes here.
Modal Title
Modal Body
ghsa-m5hm-48p4-4q77
Vulnerability from github
Published
2024-06-14 06:34
Modified
2024-06-14 06:34
Severity ?
VLAI Severity ?
Details
Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.
{ "affected": [], "aliases": [ "CVE-2024-3498" ], "database_specific": { "cwe_ids": [ "CWE-250" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T05:15:49Z", "severity": "HIGH" }, "details": "Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.", "id": "GHSA-m5hm-48p4-4q77", "modified": "2024-06-14T06:34:48Z", "published": "2024-06-14T06:34:48Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3498" }, { "type": "WEB", "url": "https://jvn.jp/en/vu/JVNVU97136265/index.html" }, { "type": "WEB", "url": "https://www.toshibatec.com/information/20240531_01.html" }, { "type": "WEB", "url": "https://www.toshibatec.com/information/pdf/information20240531_01.pdf" } ], "schema_version": "1.4.0", "severity": [ { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "type": "CVSS_V3" } ] }
CVE-2024-3498 (GCVE-0-2024-3498)
Vulnerability from cvelistv5
Published
2024-06-14 04:20
Modified
2024-08-01 20:12
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-250 - Execution with Unnecessary Privileges
Summary
Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Toshiba Tec Corporation | Toshiba Tec e-Studio multi-function peripheral (MFP) |
Version: see the reference URL |
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2521_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2521_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2020_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2020_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2520_nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2520_nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2021_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2021_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2525_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2525_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3025_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3025_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3525_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3525_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3525_acg:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3525_acg", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-4525_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-4525_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-5525_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-5525_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-5525_acg:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-5525_acg", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-6525_ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-6525_ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-6525_acg:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-6525_acg", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2528-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2528-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3028-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3028-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3528-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3528-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3528-ag:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3528-ag", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-4528-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-4528-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-4528-ag:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-4528-ag", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-5528-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-5528-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-6528-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-6528-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-6526-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-6526-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-6527-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-6527-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-7527-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-7527-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-6529-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-6529-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-7529-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-7529-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-9029-a:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-9029-a", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-330-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-330-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-400-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-400-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2010-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2010-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2110-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2110-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2510-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2510-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2610-ac:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2610-ac", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2015-nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2015-nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2515-nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2515-nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-2615-nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-2615-nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3015-nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3015-nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3115-nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3115-nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3515-nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3515-nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:h:toshibatec:e-studio-3615-nc:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "e-studio-3615-nc", "vendor": "toshibatec", "versions": [ { "lessThanOrEqual": "*", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-3498", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-14T16:34:42.877802Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-14T16:48:56.007Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T20:12:07.649Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.toshibatec.com/information/20240531_01.html" }, { "tags": [ "x_transferred" ], "url": "https://www.toshibatec.com/information/pdf/information20240531_01.pdf" }, { "tags": [ "x_transferred" ], "url": "https://jvn.jp/en/vu/JVNVU97136265/index.html" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "Linux" ], "product": "Toshiba Tec e-Studio multi-function peripheral (MFP)", "vendor": "Toshiba Tec Corporation", "versions": [ { "status": "affected", "version": "see the reference URL" } ] } ], "configurations": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "If user authentication is disabled.\u003cbr\u003e" } ], "value": "If user authentication is disabled." } ], "credits": [ { "lang": "en", "type": "finder", "value": "We expresses its gratitude to Zhenhua Huang, Harry Zhang and Minmin Li for reporting relevant security vulnerabilities for our products." } ], "datePublic": "2024-06-14T02:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL." } ], "value": "Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL." } ], "exploits": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "We are not aware of any malicious exploitation by these vulnerabilities.\u003cbr\u003e" } ], "value": "We are not aware of any malicious exploitation by these vulnerabilities." } ], "impacts": [ { "capecId": "CAPEC-233", "descriptions": [ { "lang": "en", "value": "CAPEC-233 Privilege Escalation" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-250", "description": "CWE-250 Execution with Unnecessary Privileges", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-06-14T04:20:01.103Z", "orgId": "ecc0f906-8666-484c-bcf8-c3b7520a72f0", "shortName": "Toshiba" }, "references": [ { "url": "https://www.toshibatec.com/information/20240531_01.html" }, { "url": "https://www.toshibatec.com/information/pdf/information20240531_01.pdf" }, { "url": "https://jvn.jp/en/vu/JVNVU97136265/index.html" } ], "solutions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "This issue is fixed in the version released on June 14, 2024 and all later versions.\u003cbr\u003e" } ], "value": "This issue is fixed in the version released on June 14, 2024 and all later versions." } ], "source": { "discovery": "UNKNOWN" }, "timeline": [ { "lang": "en", "time": "2024-06-14T02:00:00.000Z", "value": "Fixes will be released" } ], "title": "Incorrect Permission Assignment Privilege Escalation Vulnerability", "workarounds": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "When connecting the MFPs and printers with an outer network such as the Internet, only operate it in a network environment protected by a firewall, etc. to prevent information from being leaked due to incorrect settings or avoid illegal access by unauthorized users.\u003cbr\u003e" } ], "value": "When connecting the MFPs and printers with an outer network such as the Internet, only operate it in a network environment protected by a firewall, etc. to prevent information from being leaked due to incorrect settings or avoid illegal access by unauthorized users." } ], "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "ecc0f906-8666-484c-bcf8-c3b7520a72f0", "assignerShortName": "Toshiba", "cveId": "CVE-2024-3498", "datePublished": "2024-06-14T04:20:01.103Z", "dateReserved": "2024-04-09T00:59:41.285Z", "dateUpdated": "2024-08-01T20:12:07.649Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…