VulnerabilityAnalyzed
CVE-2024-42420
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages.
HIGH 7.5EPSS 0.75%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- toshibatec/e-studio1058 firmware · toshibatec/e-studio1208 firmware · toshibatec/e-studio908 firmware · sharp/bp-90c70 firmware · sharp/bp-90c80 firmware · sharp/bp-70c65 firmware · sharp/bp-70c55 firmware · sharp/bp-70c45 firmware · sharp/bp-70c36 firmware · sharp/bp-70c31 firmware · sharp/bp-60c45 firmware · sharp/bp-60c36 firmware · sharp/bp-60c31 firmware · sharp/bp-50c65 firmware · sharp/bp-50c55 firmware · sharp/bp-50c45 firmware · sharp/bp-50c36 firmware · sharp/bp-50c31 firmware · sharp/bp-50c26 firmware · sharp/bp-55c26 firmware · +40 more
- Source
- vultures@jpcert.or.jp
References
- https://global.sharp/products/copier/info/info_security_2024-10.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU95063136/Third Party Advisory
- https://www.toshibatec.com/information/20241025_01.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.