Local Privilege Escalation and Remote Code Execution using insecure permissions
Published Jun 14, 2024
7.4
HIGHCVSS 3.1
EPSS 0.40%
Description
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affected products/models/versions, see the reference URL.
Affected products
- Vendor Toshiba Tec Corporation Product Toshiba Tec e-Studio multi-function peripheral (MFP) Defaultunaffected
Affected
- see the reference URL
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Toshiba Tec Corporation | Toshiba Tec e-Studio multi-function peripheral (MFP) | unaffected | Affected
|
No data.
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This issue is fixed in the version released on June 14, 2024 and all later versions.
References (5)
- http://seclists.org/fulldisclosure/2024/Jul/1
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-24392 Advisory
- https://jvn.jp/en/vu/JVNVU97136265/index.html
- https://www.toshibatec.com/information/20240531_01.html
- https://www.toshibatec.com/information/pdf/information20240531_01.pdf
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data