PT-2024-21710 · Toshiba · Toshiba Tec

Pierre Barre

·

Published

2024-06-14

·

Updated

2024-07-04

·

CVE-2024-27176

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Toshiba TEC products (affected versions not specified)
Description An attacker can achieve Remote Code Execution by overwriting files, which is enabled by falsifying the session ID variable. This issue can be executed in combination with other vulnerabilities, making it difficult to execute alone.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-27176

Affected Products

Toshiba Tec