Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.
Fixes

Solution

This issue is fixed in the version released on June 14, 2024 and all later versions.


Workaround

When connecting the MFPs and printers with an outer network such as the Internet, only operate it in a network environment protected by a firewall, etc. to prevent information from being leaked due to incorrect settings or avoid illegal access by unauthorized users.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Toshiba

Published:

Updated: 2024-08-01T20:12:07.649Z

Reserved: 2024-04-09T00:59:41.285Z

Link: CVE-2024-3498

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.649Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-14T05:15:49.180

Modified: 2024-11-21T09:29:44.037

Link: CVE-2024-3498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.