Beveiligingsadvies

CVE-2024-27142

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-06-14 02:28:02
Laatst bijgewerkt 2025-02-13 17:41:21
Toegewezen door Toshiba
CVSS-score 5.9
Status PUBLISHED

Beschrijving

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.