Toshiba e-STUDIO是日本东芝(Toshiba)公司的一系列高端办公多功能打印机。 Toshiba e-STUDIO 存在安全漏洞,该漏洞源于存在未经授权访问多功能设备内部程序某些 API 的方法,因此第三方可能通过访问多功能设备来窃取信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Toshiba Tec Corporation | Toshiba Tec e-Studio multi-function peripheral (MFP) | see the reference URL | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-27173 | 9.8 CRITICAL | insecure upload |
| CVE-2024-27174 | 9.8 CRITICAL | insecure upload |
| CVE-2024-27144 | 9.8 CRITICAL | Pre-authenticated Remote Code Execution |
| CVE-2024-27145 | 9.8 CRITICAL | Multiple Post-authenticated Remote Code Execution |
| CVE-2024-27172 | 9.8 CRITICAL | Remote Code Execution |
| CVE-2024-27143 | 9.8 CRITICAL | Pre-authenticated Remote Code Execution |
| CVE-2024-3496 | 8.8 HIGH | Authentication Bypass Vulnerability |
| CVE-2024-3497 | 8.8 HIGH | Directory Traversal Remote Code Execution Vulnerability |
| CVE-2024-27165 | 7.8 HIGH | Local Privilege Escalation |
| CVE-2024-3498 | 7.8 HIGH | Incorrect Permission Assignment Privilege Escalation Vulnerability |
| CVE-2024-27155 | 7.7 HIGH | Local Privilege Escalation and Remote Code Execution using insecure permissions |
| CVE-2024-27151 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using insecure permissions |
| CVE-2024-27171 | 7.4 HIGH | Insecure permissions |
| CVE-2024-27167 | 7.4 HIGH | Insecure permissions |
| CVE-2024-27152 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using insecure permissions |
| CVE-2024-27166 | 7.4 HIGH | Insecure permissions |
| CVE-2024-27170 | 7.4 HIGH | Hardcoded credentials for WebDAV access |
| CVE-2024-27147 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using snmpd |
| CVE-2024-27149 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using insecure LD_PRELOAD |
| CVE-2024-27158 | 7.4 HIGH | Hardcoded root password |
Showing top 20 of 43 CVEs. View all on vendor page → →
No comments yet