PT-2024-21693 · Toshiba · Toshiba Printers

Pierre Barre

·

Published

2024-06-14

·

Updated

2024-07-04

·

CVE-2024-27160

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Toshiba printers (affected versions not specified)
Description The issue concerns a shell script in Toshiba printers that uses a hardcoded key for log encryption. An attacker can exploit this by decrypting the encrypted files using the hardcoded key. This issue can be difficult to execute alone and may be used in combination with other vulnerabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-27160

Affected Products

Toshiba Printers