MX-M315v Firmware
Sharp · 9 CVEs
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site sc…
Oct 25, 2024
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site sc…
Oct 25, 2024
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unint…
Oct 25, 2024
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulne…
Oct 25, 2024
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users o…
Oct 25, 2024
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability…
Oct 25, 2024
Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperl…
Oct 25, 2024
Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. C…
Oct 25, 2024
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword s…
Oct 25, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-48870 | Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input… | MEDIUM | 0.35% | Oct 25, 2024 |
| CVE-2024-47801 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a craft… | HIGH | 0.36% | Oct 25, 2024 |
| CVE-2024-47549 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Acc… | HIGH | 0.36% | Oct 25, 2024 |
| CVE-2024-47406 | Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. | CRITICAL | 0.62% | Oct 25, 2024 |
| CVE-2024-47005 | Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A no… | HIGH | 0.46% | Oct 25, 2024 |
| CVE-2024-45842 | Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retri… | MEDIUM | 0.55% | Oct 25, 2024 |
| CVE-2024-45829 | Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-b… | HIGH | 0.71% | Oct 25, 2024 |
| CVE-2024-43424 | Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected… | HIGH | 0.75% | Oct 25, 2024 |
| CVE-2024-42420 | Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of S… | HIGH | 0.75% | Oct 25, 2024 |
Showing 1 to 9 of 9 CVEs