Sharp Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Energy Management Controller with Cloud Services.
Products
Clear product- Multiple MFPs (multifunction printers)14 vulnerabilities
- Sharp Digital Full-color MFPs and Monochrome MFPs9 vulnerabilities
- Energy Management Controller with Cloud Services7 vulnerabilities
- home 5G HR026 vulnerabilities
- Wi-Fi STATION SH-54C6 vulnerabilities
- Wi-Fi STATION SH-52B5 vulnerabilities
- Sharp MFPs3 vulnerabilities
- PocketWifi 809SH2 vulnerabilities
- Speed Wi-Fi NEXT W072 vulnerabilities
- Wi-Fi STATION SH-05L2 vulnerabilities
- 5G Mobile Router SH-U011 vulnerability
- home 5G HR011 vulnerability
- Network Scanner Tool (Bundled software for Sharpdesk)1 vulnerability
- Network Scanner Tool Lite1 vulnerability
- Pocket WiFi 5G A503SH1 vulnerability
- RW-4040 driver installer for Windows 71 vulnerability
- RW-4040 tool to verify execution environment for Windows 71 vulnerability
- RW-5100 driver installer for Windows 71 vulnerability
- RW-5100 driver installer for Windows 8.11 vulnerability
- RW-5100 tool to verify execution environment for Windows 71 vulnerability
- RW-5100 tool to verify execution environment for Windows 8.11 vulnerability
- RX-CLV1-P firmware1 vulnerability
- RX-CLV2-B firmware1 vulnerability
- RX-CLV3-N firmware1 vulnerability
- RX-V100 firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-23789CRITICAL | Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product. CWE-78Feb 14, 2024 | CVSS9.8v3.1 | EPSS1.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23788CRITICAL | Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product. CWE-918Feb 14, 2024 | CVSS9.1v3.1 | EPSS0.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23787HIGH | Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product. CWE-22Feb 14, 2024 | CVSS7.5v3.1 | EPSS0.892% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23786CRITICAL | Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product. CWE-79Feb 14, 2024 | CVSS9.3v3.1 | EPSS0.786% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23785MEDIUM | Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings. CWE-352Feb 14, 2024 | CVSS6.5v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23784MEDIUM | Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displayed on the management page of the affected product. Feb 14, 2024 | CVSS6.5v3.1 | EPSS0.393% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23783HIGH | Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication. CWE-306Feb 14, 2024 | CVSS8.8v3.1 | EPSS0.519% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |