Record summary

CVE-2023-34259 has a selected CVSS score of 4.9 (medium); EIP currently links 1 Nuclei template.

Description

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 6, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListThrough 2VG_S000.002.561affected

Nuclei templates

1
ProjectDiscoveryMEDIUMKyocera TASKalfa printer - Path TraversalCVSS 4.9

CCRX has a Path Traversal vulnerability. Path Traversal is an attack on web applications. By manipulating the value of the file path, an attacker can gain access to the file system, including source code and critical system settings.

Impact

Unauthenticated attackers can manipulate file path values to access sensitive file system resources including source code and critical system configuration files.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-22
Authorsgy741
Template tagscvecve2023packetstormseclistskyoceralfiprintervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:kyocera:d-copia253mf_plus_firmware:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-50306417
FOFA: icon_hash=-50306417

Source: ProjectDiscovery

References

3