seclists.org
http://seclists.org/fulldisclosure/2024/Jul/0 CVE-2024-34162
MEDIUM
Record summary
CVE-2024-34162 has a selected CVSS score of 5.3 (medium).
Description
The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Multiple MFPs (multifunction printers)Browse Sharp Corporation / Multiple MFPs (multifunction printers) | CVE List | See the information provided by Sharp Corporation listed under [References] | affected |
Multiple MFPs (multifunction printers)Browse Toshiba Tec Corporation / Multiple MFPs (multifunction printers) | CVE List | See the information provided by Toshiba Tec Corporation listed under [References] | affected |
References
8global.sharp
https://global.sharp/products/copier/info/info_security_2024-05.html jp.sharp
https://jp.sharp/business/print/information/info_security_2024-05.html jvn.jp
https://jvn.jp/en/vu/JVNVU93051062 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-34162 pierrekim.github.io
https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html toshibatec.co.jp
https://www.toshibatec.co.jp/information/20240531_02.html toshibatec.com
https://www.toshibatec.com/information/20240531_02.html