PT-2024-21672 · Toshiba · Toshiba Printers

Pierre Barre

·

Published

2024-06-14

·

Updated

2024-07-04

·

CVE-2024-27141

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Toshiba printers (affected versions not specified)
Description The issue concerns a time-based blind XML External Entity (XXE) vulnerability in the XML parsing library used by the API endpoint of Toshiba printers. This vulnerability can be exploited to retrieve information or to cause a Denial of Service (DoS) by sending an HTTP request without authentication. The API endpoint uses XML communication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XML Entity Expansion

Weakness Enumeration

Related Identifiers

CVE-2024-27141

Affected Products

Toshiba Printers