Sharp Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Multiple MFPs (multifunction printers).
Products
Clear product- Multiple MFPs (multifunction printers)14 vulnerabilities
- Sharp Digital Full-color MFPs and Monochrome MFPs9 vulnerabilities
- Energy Management Controller with Cloud Services7 vulnerabilities
- home 5G HR026 vulnerabilities
- Wi-Fi STATION SH-54C6 vulnerabilities
- Wi-Fi STATION SH-52B5 vulnerabilities
- Sharp MFPs3 vulnerabilities
- PocketWifi 809SH2 vulnerabilities
- Speed Wi-Fi NEXT W072 vulnerabilities
- Wi-Fi STATION SH-05L2 vulnerabilities
- 5G Mobile Router SH-U011 vulnerability
- home 5G HR011 vulnerability
- Network Scanner Tool (Bundled software for Sharpdesk)1 vulnerability
- Network Scanner Tool Lite1 vulnerability
- Pocket WiFi 5G A503SH1 vulnerability
- RW-4040 driver installer for Windows 71 vulnerability
- RW-4040 tool to verify execution environment for Windows 71 vulnerability
- RW-5100 driver installer for Windows 71 vulnerability
- RW-5100 driver installer for Windows 8.11 vulnerability
- RW-5100 tool to verify execution environment for Windows 71 vulnerability
- RW-5100 tool to verify execution environment for Windows 8.11 vulnerability
- RX-CLV1-P firmware1 vulnerability
- RX-CLV2-B firmware1 vulnerability
- RX-CLV3-N firmware1 vulnerability
- RX-V100 firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-36254HIGH | Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition. CWE-125Nov 26, 2024 | CVSS7.5v3.1 | EPSS0.689% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36251HIGH | The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-125Nov 26, 2024 | CVSS7.5v3.1 | EPSS3.52% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36249HIGH | Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-79Nov 26, 2024 | CVSS7.4v3.1 | EPSS0.527% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36248CRITICAL | API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-798Nov 26, 2024 | CVSS9.1v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35244CRITICAL | There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-798Nov 26, 2024 | CVSS9.1v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34162MEDIUM | The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-767Nov 26, 2024 | CVSS5.3v3.1 | EPSS0.785% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33616MEDIUM | Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the feature. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-306Nov 26, 2024 | CVSS5.3v3.1 | EPSS0.909% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33610CRITICAL | Sharp Multifunction Printers - Cookie Exposure"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. | CVSS9.1v3.1 | EPSS45.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-33605HIGH | Sharp Multifunction Printers - Directory ListingImproper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. | CVSS7.5v3.1 | EPSS6.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-32151MEDIUM | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-257Nov 26, 2024 | CVSS5.9v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29978MEDIUM | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-256Nov 26, 2024 | CVSS5.9v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29146MEDIUM | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-312Nov 26, 2024 | CVSS5.9v3.1 | EPSS0.853% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28955MEDIUM | Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-732Nov 26, 2024 | CVSS5.9v3.1 | EPSS1.34% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28038CRITICAL | The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. CWE-121Nov 26, 2024 | CVSS9.0v3.1 | EPSS2.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |