seclists.org
http://seclists.org/fulldisclosure/2024/Jul/0 CVE-2024-28038
CRITICAL
Record summary
CVE-2024-28038 has a selected CVSS score of 9.0 (critical).
Description
The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Multiple MFPs (multifunction printers)Browse Sharp Corporation / Multiple MFPs (multifunction printers) | CVE List | See the information provided by Sharp Corporation listed under [References] | affected |
Multiple MFPs (multifunction printers)Browse Toshiba Tec Corporation / Multiple MFPs (multifunction printers) | CVE List | See the information provided by Toshiba Tec Corporation listed under [References] | affected |
References
8global.sharp
https://global.sharp/products/copier/info/info_security_2024-05.html jp.sharp
https://jp.sharp/business/print/information/info_security_2024-05.html jvn.jp
https://jvn.jp/en/vu/JVNVU93051062 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-28038 pierrekim.github.io
https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html toshibatec.co.jp
https://www.toshibatec.co.jp/information/20240531_02.html toshibatec.com
https://www.toshibatec.com/information/20240531_02.html