VulnerabilityAnalyzed
CVE-2024-45842
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.
MEDIUM 5.3EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- toshibatec/e-studio1058 firmware · toshibatec/e-studio1208 firmware · toshibatec/e-studio908 firmware · sharp/bp-90c70 firmware · sharp/bp-90c80 firmware · sharp/bp-70c65 firmware · sharp/bp-70c55 firmware · sharp/bp-70c45 firmware · sharp/bp-70c36 firmware · sharp/bp-70c31 firmware · sharp/bp-60c45 firmware · sharp/bp-60c36 firmware · sharp/bp-60c31 firmware · sharp/bp-50c65 firmware · sharp/bp-50c55 firmware · sharp/bp-50c45 firmware · sharp/bp-50c36 firmware · sharp/bp-50c31 firmware · sharp/bp-50c26 firmware · sharp/bp-55c26 firmware · +40 more
- Source
- vultures@jpcert.or.jp
References
- https://global.sharp/products/copier/info/info_security_2024-10.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU95063136/Third Party Advisory
- https://www.toshibatec.com/information/20241025_01.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.