Record summary

CVE-2024-33605 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListSee the information provided by Sharp Corporation listed under [References]affected
CVE ListSee the information provided by Toshiba Tec Corporation listed under [References]affected

Nuclei templates

1
ProjectDiscoveryHIGHSharp Multifunction Printers - Directory ListingCVSS 7.5

It was observed that Sharp printers are vulnerable to an arbitrary directory listing without authentication. Any attacker can list any directory located in the printer and recover any file.

Impact

Unauthenticated attackers can list arbitrary directories and recover files from Sharp multifunction printers.

Remediation

Apply all relevant security patches and product upgrades for Sharp multifunction printers.

WeaknessesCWE-22
Authorsgy741
Template tagscvecve2024sharpprintertraversalvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:sharp:mx-3550v_firmware:*:*:*:*:*:*:*:*
Shodan: Set-Cookie: MFPSESSIONID=

Source: ProjectDiscovery

References

8