CVE-2024-47005

Published Oct 25, 2024

Last updated 12 days ago

Overview

Description
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.
Source
vultures@jpcert.or.jp
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-Other
vultures@jpcert.or.jp
CWE-749

Social media

Hype score
Not currently trending

Configurations