- Description
- The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running "ps aux" as the root user and observing the output.
- Source
- 551230f0-3615-47bd-b7cc-93e92e730bbf
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 6.1
- Impact score
- 5.2
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- MEDIUM
- 551230f0-3615-47bd-b7cc-93e92e730bbf
- CWE-250
- Hype score
- Not currently trending
CVE-2024-28140 The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user.… https://t.co/FgY5BcVu1r
@CVEnew
15 Dec 2024
489 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-28140 SEC Consult SA-20241204-0 : Multiple Critical Vulnerabilities in Image Access Scan2Net (14 CVE) https://t.co/RAWqYH0Non
@VulmonFeeds
5 Dec 2024
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes