Record summary

CVE-2024-34162 has a selected CVSS score of 5.3 (medium).

Description

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListSee the information provided by Sharp Corporation listed under [References]affected
CVE ListSee the information provided by Toshiba Tec Corporation listed under [References]affected

References

8