CVE-2024-47406
CVE-2024-47406
9.1
CriticalPublished:
Last updated:
Source:vultures@jpcert.or.jp
Analyzed
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- None
- Availability
- High
Description
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.
References
vultures@jpcert.or.jp
https://global.sharp/products/copier/info/info_security_2024-10.htmlvultures@jpcert.or.jp
https://jvn.jp/en/vu/JVNVU95063136/vultures@jpcert.or.jp
https://www.toshibatec.com/information/20241025_01.html