PT-2024-25375 · Sharp+1 · Multiple Mfps

Morgan Davies

·

Published

2024-11-26

·

Updated

2024-12-01

·

CVE-2024-33610

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions No specific software name and version are mentioned in the provided descriptions.
Description The issue concerns the accessibility of certain web pages, specifically "sessionlist.html" and "sys trayentryreboot.html", without requiring authentication. The "sessionlist.html" page provides information about logged-in users' sessions, including session cookies, while the "sys trayentryreboot.html" page allows for the rebooting of the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-33610

Affected Products

Multiple Mfps