SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-47549

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers.

MEDIUM 6.1EPSS 0.34%

Does this matter?

Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.

Description

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.34% probability · 27th percentile
CISA KEV
Not listed
Weakness
CWE-644, CWE-116
Affected
toshibatec/e-studio1058 firmware · toshibatec/e-studio1208 firmware · toshibatec/e-studio908 firmware · sharp/bp-90c70 firmware · sharp/bp-90c80 firmware · sharp/bp-70c65 firmware · sharp/bp-70c55 firmware · sharp/bp-70c45 firmware · sharp/bp-70c36 firmware · sharp/bp-70c31 firmware · sharp/bp-60c45 firmware · sharp/bp-60c36 firmware · sharp/bp-60c31 firmware · sharp/bp-50c65 firmware · sharp/bp-50c55 firmware · sharp/bp-50c45 firmware · sharp/bp-50c36 firmware · sharp/bp-50c31 firmware · sharp/bp-50c26 firmware · sharp/bp-55c26 firmware · +40 more
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.