PT-2024-21711 · Toshiba · Toshiba

Pierre Barre

·

Published

2024-06-14

·

Updated

2024-07-04

·

CVE-2024-27177

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Toshiba product (affected versions not specified)
Description An attacker can achieve Remote Code Execution by overwriting files, which is enabled by falsifying the package name variable. This issue can be executed in combination with other vulnerabilities and is difficult to execute alone.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-27177

Affected Products

Toshiba