Toshiba e-STUDIO是日本东芝(Toshiba)公司的一系列高端办公多功能打印机。 Toshiba e-STUDIO 存在安全漏洞,该漏洞源于如果禁用用户身份验证,则可以通过从 MFP 的 Web 界面启用服务来执行恶意文件,从而将其权限提升到 root。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Toshiba Tec Corporation | Toshiba Tec e-Studio multi-function peripheral (MFP) | see the reference URL | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-27144 | 9.8 CRITICAL | Pre-authenticated Remote Code Execution |
| CVE-2024-27173 | 9.8 CRITICAL | insecure upload |
| CVE-2024-27172 | 9.8 CRITICAL | Remote Code Execution |
| CVE-2024-27174 | 9.8 CRITICAL | insecure upload |
| CVE-2024-27145 | 9.8 CRITICAL | Multiple Post-authenticated Remote Code Execution |
| CVE-2024-27143 | 9.8 CRITICAL | Pre-authenticated Remote Code Execution |
| CVE-2024-3496 | 8.8 HIGH | Authentication Bypass Vulnerability |
| CVE-2024-3497 | 8.8 HIGH | Directory Traversal Remote Code Execution Vulnerability |
| CVE-2024-27169 | 8.4 HIGH | Lack of authentication |
| CVE-2024-27165 | 7.8 HIGH | Local Privilege Escalation |
| CVE-2024-27155 | 7.7 HIGH | Local Privilege Escalation and Remote Code Execution using insecure permissions |
| CVE-2024-27152 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using insecure permissions |
| CVE-2024-27153 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution |
| CVE-2024-27171 | 7.4 HIGH | Insecure permissions |
| CVE-2024-27151 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using insecure permissions |
| CVE-2024-27147 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using snmpd |
| CVE-2024-27167 | 7.4 HIGH | Insecure permissions |
| CVE-2024-27166 | 7.4 HIGH | Insecure permissions |
| CVE-2024-27149 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using insecure LD_PRELOAD |
| CVE-2024-27148 | 7.4 HIGH | Local Privilege Escalation and Remote Code Execution using insecure PATH |
Showing top 20 of 43 CVEs. View all on vendor page → →
No comments yet