CVE-2012-1239
The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.67% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- toshibatec/e-studio-167 with network printer kit firmware · toshibatec/e-studio-181 with network printer kit firmware · toshibatec/e-studio-182 with network printer kit firmware · toshibatec/e-studio-207 with network printer kit firmware · toshibatec/e-studio-232 firmware · toshibatec/e-studio-2330c firmware · toshibatec/e-studio-2500c firmware · toshibatec/e-studio-255 firmware · toshibatec/e-studio-255p firmware · toshibatec/e-studio-281c firmware · toshibatec/e-studio-282 firmware · toshibatec/e-studio-2830c firmware · toshibatec/e-studio-3500c firmware · toshibatec/e-studio-3510c firmware · toshibatec/e-studio-351c firmware · toshibatec/e-studio-352 firmware · toshibatec/e-studio-3520c firmware · toshibatec/e-studio-355 firmware · toshibatec/e-studio-451c firmware · toshibatec/e-studio-452 firmware · +40 more
- Source
- vultures@jpcert.or.jp
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.