Record summary

CVE-2024-28038 has a selected CVSS score of 9.0 (critical).

Description

The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListSee the information provided by Sharp Corporation listed under [References]affected
CVE ListSee the information provided by Toshiba Tec Corporation listed under [References]affected

References

8