CVE-2024-27170: Hardcoded credentials for WebDAV access
It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a full access with WebDAV to the printer. As for the affected products/models/versions, see the reference URL.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27170?
CVE-2024-27170 is considered a high severity vulnerability due to the potential for unauthorized full access to Toshiba printers.
How do I fix CVE-2024-27170?
To mitigate CVE-2024-27170, users should update the firmware of their Toshiba printers to the latest version provided by Toshiba.
What types of printers are affected by CVE-2024-27170?
CVE-2024-27170 affects various models of Toshiba printers that contain exposed WebDAV credentials.
What kind of access does CVE-2024-27170 provide to attackers?
CVE-2024-27170 allows attackers full access to the affected Toshiba printers via WebDAV.
Is there a known exploitation method for CVE-2024-27170?
Yes, exploitation of CVE-2024-27170 involves using the exposed WebDAV credentials to gain unauthorized access to printer functionalities.