CVE-2024-27170
It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a full access with WebDAV to the printer. As for the affected products/models/versions, see the reference URL.
- Affected products
- Toshiba Printers
- CVSS 3.1
- 7.4 HIGH
- EPSS
- 0.3% (20th percentile)
- Weakness
- CWE-798
- NVD status
- Deferred
- Published
- 2024-06-14
- Attack patterns
- CAPEC-37
- Entry point
- <DeviceInformationModel>... request body
- Path
- contentwebserver
Fix
This issue is fixed in the version released on June 14, 2024 and all later versions.
CVE-2024-27170 at NVD
1 known exploit for CVE-2024-27170
Proof-of-concept code and exploit modules indexed by Sploitus