It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-24409 | It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL. |
Fixes
Solution
This issue is fixed in the version released on June 14, 2024 and all later versions.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Toshiba
Published:
Updated: 2025-02-13T17:46:10.504Z
Reserved: 2024-02-21T02:11:59.653Z
Link: CVE-2024-27168
Updated: 2024-08-02T00:27:59.645Z
Status : Awaiting Analysis
Published: 2024-06-14T04:15:34.900
Modified: 2024-11-21T09:04:00.433
Link: CVE-2024-27168
No data.
OpenCVE Enrichment
No data.
EUVD