It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Toshiba
Published: 2024-06-14T03:53:58.804Z
Updated: 2024-08-02T00:27:59.645Z
Reserved: 2024-02-21T02:11:59.653Z
Link: CVE-2024-27168
Vulnrichment
Updated: 2024-08-02T00:27:59.645Z
NVD
Status : Awaiting Analysis
Published: 2024-06-14T04:15:34.900
Modified: 2024-11-21T09:04:00.433
Link: CVE-2024-27168
Redhat
No data.