CVE-2024-27166
7.4
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.4 / Impact: 5.9
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0 (Secondary)
Description
Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the reference URL.
Related CWEs
CWE-256
Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.
CWE-276
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CWE-319
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
References (8)
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.