PT-2024-22642 · Toshiba · Sharp/Toshiba Tec Mfps

Pierre Barre

·

Published

2024-07-01

·

Updated

2024-11-26

·

CVE-2024-28955

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sharp/Toshiba Tec MFPs (affected versions not specified)
Description The issue allows any local user of the device to examine coredump files, which are stored with world-readable permission when the device crashes. This enables the user to research the memory contents. The flaw is related to incorrect permission assignment, potentially leading to unauthorized access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2024-28955

Affected Products

Sharp/Toshiba Tec Mfps