CVE-2024-28955
CVE-2024-28955
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Produtos afetados
Sharp Corporation · Multiple MFPs (multifunction printers)Toshiba Tec Corporation · Multiple MFPs (multifunction printers)Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://seclists.org/fulldisclosure/2024/Jul/0https://global.sharp/products/copier/info/info_security_2024-05.htmlhttps://jp.sharp/business/print/information/info_security_2024-05.htmlhttps://jvn.jp/en/vu/JVNVU93051062/https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.htmlhttps://www.toshibatec.co.jp/information/20240531_02.htmlhttps://www.toshibatec.com/information/20240531_02.html