CVE-2024-47005
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47005?
CVE-2024-47005 has been classified as a medium severity vulnerability due to insufficient access controls on configuration APIs.
How can I fix CVE-2024-47005?
To fix CVE-2024-47005, ensure that the configuration-related APIs are properly restricted to administrative users only.
Which products are affected by CVE-2024-47005?
CVE-2024-47005 affects Sharp and Toshiba Tec multifunction printers, specifically certain firmware versions of models like e-Studio and MX series.
What type of vulnerability is CVE-2024-47005?
CVE-2024-47005 is an access control vulnerability that allows non-administrative users to execute sensitive configuration APIs.
Is there a patch available for CVE-2024-47005?
Yes, patches or updates for affected printers should be provided by the manufacturers to rectify the vulnerability.