CVE-2024-58388
Beschrijving NL
Sharp (en Toshiba Tec omgedoopt) multifunctionele printers bevatten een niet-geverifieerde kwetsbaarheid voor het opnemen van lokale bestanden waarmee externe aanvallers willekeurige bestanden kunnen lezen door de padparameter in het installed_emanual_down.html-eindpunt te manipuleren. Aanvallers kunnen directorytraversal-sequenties leveren zoals Path=/manual/../../../ om toegang te krijgen tot bestanden buiten de beoogde handmatige map, inclusief /etc/passwd, coredump-bestanden met referenties en systeemconfiguratiebestanden. Exploitatiebewijs werd voor het eerst waargenomen door de Shadowserver Foundation op 30-07-2024.
Origineel (Engels) tonen
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../ to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.