Description
It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.
No analysis available yet.
Remediation
Vendor Solution
This issue is fixed in the version released on June 14, 2024 and all later versions.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-24409 | It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL. |
References
History
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Toshiba
Published:
Updated: 2025-02-13T17:46:10.504Z
Reserved: 2024-02-21T02:11:59.653Z
Link: CVE-2024-27168
Updated: 2024-08-02T00:27:59.645Z
Status : Deferred
Published: 2024-06-14T04:15:34.900
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-27168
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD