CVE-2023-34259
Kyocera TASKalfa printer - Path Traversal
Record summary
CVE-2023-34259 has a selected CVSS score of 4.9 (medium); EIP currently links 1 Nuclei template.
Description
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 6, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
taskalfa_4053ciBrowse kyocera / taskalfa_4053ciDefault status: unknown | CVE List | Through 2VG_S000.002.561 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMKyocera TASKalfa printer - Path TraversalCVSS 4.9
CCRX has a Path Traversal vulnerability. Path Traversal is an attack on web applications. By manipulating the value of the file path, an attacker can gain access to the file system, including source code and critical system settings.
Impact
Unauthenticated attackers can manipulate file path values to access sensitive file system resources including source code and critical system configuration files.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery