CVE-2024-33605
Sharp Multifunction Printers - Directory Listing
Record summary
CVE-2024-33605 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Multiple MFPs (multifunction printers)Browse Sharp Corporation / Multiple MFPs (multifunction printers) | CVE List | See the information provided by Sharp Corporation listed under [References] | affected |
Multiple MFPs (multifunction printers)Browse Toshiba Tec Corporation / Multiple MFPs (multifunction printers) | CVE List | See the information provided by Toshiba Tec Corporation listed under [References] | affected |
Nuclei templates
1ProjectDiscoveryHIGHSharp Multifunction Printers - Directory ListingCVSS 7.5
It was observed that Sharp printers are vulnerable to an arbitrary directory listing without authentication. Any attacker can list any directory located in the printer and recover any file.
Impact
Unauthenticated attackers can list arbitrary directories and recover files from Sharp multifunction printers.
Remediation
Apply all relevant security patches and product upgrades for Sharp multifunction printers.
Source: ProjectDiscovery