Record summary

CVE-2020-23575 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBKyocera Printer d-COPIA253MF - Directory Traversal (PoC)ExploitDB exploitby Hakan Eren ŞANNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHKyocera Printer d-COPIA253MF - Directory TraversalCVSS 7.5

Kyocera Printer d-COPIA253MF plus is susceptible to a directory traversal vulnerability which could allow an attacker to retrieve or view arbitrary files from the affected server.

Impact

An attacker can exploit this vulnerability to read arbitrary files from the server, potentially leading to unauthorized access or sensitive information disclosure.

Remediation

Apply the latest firmware update provided by Kyocera to fix the directory traversal vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2020cveprinteriotlfiedbkyoceravkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:kyocera:d-copia253mf_plus_firmware:-:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-50306417
FOFA: icon_hash=-50306417

Source: ProjectDiscovery

References

2