PT-2024-21701 · Toshiba Tec · Toshiba Tec E-Studio Multi-Function Peripheral

Pierre Barre

·

Published

2024-06-14

·

Updated

2024-07-04

·

CVE-2024-27168

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Product Name (affected versions not specified)
Description The issue involves hardcoded keys used for authentication to an internal API. If an attacker obtains these private keys, they may bypass authentication and access administrative interfaces.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-27168

Affected Products

Toshiba Tec E-Studio Multi-Function Peripheral