CVE-2024-3496

HIGH

Toshiba Tec e-Studio multi-function peripheral (MFP) - Authentication Bypass via Web Login

Title source: llm
STIX 2.1

Description

Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for the affected products/models/versions, see the reference URL.

Scores

CVSS v3 8.8
EPSS 0.0070
EPSS Percentile 48.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
Toshiba Tec Corporation/Toshiba Tec e-Studio multi-function peripheral (MFP) see the reference URL
Published Jun 14, 2024
Tracked Since Feb 18, 2026