PT-2023-24781 · Kyocera · Kyocera Taskalfa 4053Ci

Gorazd Jank

+1

·

Publicado

2023-11-02

·

Atualizado

2026-03-10

·

CVE-2023-34259

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kyocera TASKalfa 4053ci printers versions 2VG S000.002.561 and earlier
Description The issue allows directory traversal to read arbitrary files on the filesystem, even files that require root privileges, via the /wlmdeu%2f%2e%2e%2f%2e%2e endpoint. This is due to an incomplete fix for a previous issue.
Recommendations For versions 2VG S000.002.561 and earlier, as a temporary workaround, consider restricting access to the /wlmdeu%2f%2e%2e%2f%2e%2e endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34259

Produtos afetados

Kyocera Taskalfa 4053Ci