CVE-2020-23575
kyocera d-copia253mf_plus_firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2020-23575 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
d-copia253mf_plus_firmwareBrowse kyocera / d-copia253mf_plus_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBKyocera Printer d-COPIA253MF - Directory Traversal (PoC)ExploitDB exploitby Hakan Eren ŞANNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHKyocera Printer d-COPIA253MF - Directory TraversalCVSS 7.5
Kyocera Printer d-COPIA253MF plus is susceptible to a directory traversal vulnerability which could allow an attacker to retrieve or view arbitrary files from the affected server.
Impact
An attacker can exploit this vulnerability to read arbitrary files from the server, potentially leading to unauthorized access or sensitive information disclosure.
Remediation
Apply the latest firmware update provided by Kyocera to fix the directory traversal vulnerability.
Source: ProjectDiscovery