Search

Find a vulnerability

Search criteria

    47 vulnerabilities by TOSHIBA

    JVNDB-2026-020742

    Vulnerability from jvndb - Published: 2026-06-26 00:52 - Updated:2026-06-26 00:52
    Severity
    Summary
    Generic IO & Memory Access driver for TOSHIBA and Dynabook PCs exposes its IOCTL with insufficient access control
    Details
    Generic IO & Memory Access driver is part of a utility to configure BIOS/Supervisor passwords from within Windows. This driver is installed on PCs provided by TOSHIBA CORPORATION and Dynabook Inc. between 2009 and 2016. The driver contains the following vulnerability.
    • Exposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-56129
      • The CVSS assessment above assumes that a user with no administrative privilege accesses physical memory.
    Akshit Yadav (valium) reported this vulnerability to the developer. The developer reported the case to JPCERT/CC to notify users of the solution through JVN.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-020742.html",
      "dc:date": "2026-06-26T09:52+09:00",
      "dcterms:issued": "2026-06-26T09:52+09:00",
      "dcterms:modified": "2026-06-26T09:52+09:00",
      "description": "Generic IO \u0026 Memory Access driver is part of a utility to configure BIOS/Supervisor passwords from within Windows. This driver is installed on PCs provided by TOSHIBA CORPORATION and Dynabook Inc. between 2009 and 2016.\r\nThe driver contains the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/782.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eExposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-56129\u003c/li\u003e\u003cul\u003e\u003cli\u003eThe CVSS assessment above assumes that a user with no administrative privilege accesses physical memory.\u003c/li\u003e\u003c/ul\u003e\u003c/ul\u003eAkshit Yadav (valium) reported this vulnerability to the developer. The developer reported the case to JPCERT/CC to notify users of the solution through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-020742.html",
      "sec:cpe": {
        "#text": "cpe:/a:toshiba:generic_io_and_memory_access_driver",
        "@product": "Generic IO \u0026 Memory Access driver",
        "@vendor": "TOSHIBA",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "5.5",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-020742",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU91051826/index.html",
          "@id": "JVNVU#91051826",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-56129",
          "@id": "CVE-2026-56129",
          "@source": "CVE"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/782.html",
          "@id": "CWE-782",
          "@title": "Exposed IOCTL with Insufficient Access Control(CWE-782)"
        }
      ],
      "title": "Generic IO \u0026 Memory Access driver for TOSHIBA and Dynabook PCs exposes its IOCTL with insufficient access control"
    }

    JVNDB-2017-000091

    Vulnerability from jvndb - Published: 2017-05-16 06:46 - Updated:2017-12-21 10:16
    Severity
    Summary
    FlashAir do not set credential information in PhotoShare
    Details
    FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the image data in a certain folder with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare. When enabling PhotoShare with a mobile application (either for Android or iOS), the application prompts a user to set credentials. But when enabling PhotoShare with web browsers, the wireless LAN connection for PhotoShare cannot be enabled, and default credentials are set to the other wireless network configured to the device. As a result, a remote attacker with access to the wireless LAN may obtain image data by using default credentials (CWE-284). Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000091.html",
      "dc:date": "2017-12-21T19:16+09:00",
      "dcterms:issued": "2017-05-16T15:46+09:00",
      "dcterms:modified": "2017-12-21T19:16+09:00",
      "description": "FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the image data in a certain folder with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare.\r\n\r\nWhen enabling PhotoShare with a mobile application (either for Android or iOS), the application prompts a user to set credentials. But when enabling PhotoShare with web browsers, the wireless LAN connection for PhotoShare cannot be enabled, and default credentials are set to the other wireless network configured to the device. As a result, a remote attacker with access to the wireless LAN may obtain image data by using default credentials (CWE-284).\r\n\r\nTakayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000091.html",
      "sec:cpe": {
        "#text": "cpe:/a:toshiba:flashair",
        "@product": "FlashAir",
        "@vendor": "TOSHIBA",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "3.3",
          "@severity": "Low",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:N/C:P/I:N/A:N",
          "@version": "2.0"
        },
        {
          "@score": "4.3",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000091",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN81820501/index.html",
          "@id": "JVN#81820501",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2162",
          "@id": "CVE-2017-2162",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2162",
          "@id": "CVE-2017-2162",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "FlashAir do not set credential information in PhotoShare"
    }

    JVNDB-2017-000090

    Vulnerability from jvndb - Published: 2017-05-16 06:34 - Updated:2017-12-21 10:13
    Severity
    Summary
    FlashAir fails to restrict access permissions in PhotoShare
    Details
    FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the selected data with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare. FlashAir fails to restrict access permissions (CWE-425) in PhotoShare. Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html",
      "dc:date": "2017-12-21T19:13+09:00",
      "dcterms:issued": "2017-05-16T15:34+09:00",
      "dcterms:modified": "2017-12-21T19:13+09:00",
      "description": "FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the selected data with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare.\r\n\r\nFlashAir fails to restrict access permissions (CWE-425) in PhotoShare.\r\n\r\nTakayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html",
      "sec:cpe": {
        "#text": "cpe:/a:toshiba:flashair",
        "@product": "FlashAir",
        "@vendor": "TOSHIBA",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "2.7",
          "@severity": "Low",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:S/C:P/I:N/A:N",
          "@version": "2.0"
        },
        {
          "@score": "3.5",
          "@severity": "Low",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000090",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN46372675/index.html",
          "@id": "JVN#46372675",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2161",
          "@id": "CVE-2017-2161",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2161",
          "@id": "CVE-2017-2161",
          "@source": "NVD"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/284.html",
          "@id": "CWE-284",
          "@title": "Improper Access Control(CWE-284)"
        }
      ],
      "title": "FlashAir fails to restrict access permissions in PhotoShare"
    }

    JVNDB-2017-000069

    Vulnerability from jvndb - Published: 2017-04-14 05:09 - Updated:2017-12-21 08:50
    Severity
    Summary
    Multiple installers of Toshiba memory card related software may insecurely load Dynamic Link Libraries
    Details
    Multiple installers of Toshiba memory card related software contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Yuji Tounai of NTT Communications Corporation reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000069.html",
      "dc:date": "2017-12-21T17:50+09:00",
      "dcterms:issued": "2017-04-14T14:09+09:00",
      "dcterms:modified": "2017-12-21T17:50+09:00",
      "description": "Multiple installers of Toshiba memory card related software contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).\r\n\r\nYuji Tounai of NTT Communications Corporation reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000069.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:toshiba:nfc_sdhc_%2F_sdxc_memory_card_software_updatetool",
          "@product": "SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
          "@vendor": "TOSHIBA",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:toshiba:sdhc_memory_card_with_transferjet_firmware_updatetool",
          "@product": "SDHC Memory Card with embedded TransferJet functionality Software Update tool",
          "@vendor": "TOSHIBA",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:toshiba:sdhc_memory_card_with_transferjet_setting_software",
          "@product": "SDHC Memory Card with embedded TransferJet functionality Configuration Software",
          "@vendor": "TOSHIBA",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:toshiba:wlan_sdhc_memory_card_flashair_setting_software",
          "@product": "SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software",
          "@vendor": "TOSHIBA",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:toshiba:wlan_sdhc_memory_card_flashair_setting_software_updatetool",
          "@product": "SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool",
          "@vendor": "TOSHIBA",
          "@version": "2.2"
        }
      ],
      "sec:cvss": [
        {
          "@score": "6.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "7.8",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000069",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN05340816/index.html",
          "@id": "JVN#05340816",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2149",
          "@id": "CVE-2017-2149",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2149",
          "@id": "CVE-2017-2149",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple installers of Toshiba memory card related software may insecurely load Dynamic Link Libraries"
    }

    JVNDB-2016-000168

    Vulnerability from jvndb - Published: 2016-10-12 01:03 - Updated:2017-11-27 08:04
    Severity
    Summary
    Toshiba FlashAir does not require authentication in "Internet pass-thru Mode"
    Details
    FlashAir by Toshiba Corporation is a SDHC memory card which provides "Internet pass-thru Mode", allowing devices to access the internet while connecting to FlashAir. When configured in "Internet pass-thru Mode", FlashAir acts both as a station and as an access point. When "Internet pass-thru Mode" is enabled, FlashAir does not require authentication on accepting a connection from STA (station) side LAN. Tsukada Nobuhisa of Seasoft reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000168.html",
      "dc:date": "2017-11-27T17:04+09:00",
      "dcterms:issued": "2016-10-12T10:03+09:00",
      "dcterms:modified": "2017-11-27T17:04+09:00",
      "description": "FlashAir by Toshiba Corporation is a SDHC memory card which provides \"Internet pass-thru Mode\", allowing devices to access the internet while connecting to FlashAir. When configured in \"Internet pass-thru Mode\", FlashAir acts both as a station and as an access point.\r\nWhen \"Internet pass-thru Mode\" is enabled, FlashAir does not require authentication on accepting a connection from STA (station) side LAN.\r\n\r\nTsukada Nobuhisa of Seasoft reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000168.html",
      "sec:cpe": {
        "#text": "cpe:/a:toshiba:flashair",
        "@product": "FlashAir",
        "@vendor": "TOSHIBA",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "5.4",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:A/AC:M/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "5.0",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2016-000168",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN39619137/index.html",
          "@id": "JVN#39619137",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4863",
          "@id": "CVE-2016-4863",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2016-4863",
          "@id": "CVE-2016-4863",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-264",
          "@title": "Permissions(CWE-264)"
        }
      ],
      "title": "Toshiba FlashAir does not require authentication in \"Internet pass-thru Mode\""
    }

    JVNDB-2016-000133

    Vulnerability from jvndb - Published: 2016-08-04 04:41 - Updated:2017-05-23 05:28
    Severity
    Summary
    Coordinate Plus App fails to verify SSL server certificates
    Details
    Coordinate Plus App provided by Toshiba Corporation fails to verify SSL server certificates. Gaku Taniguchi of RiskFinder,inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html",
      "dc:date": "2017-05-23T14:28+09:00",
      "dcterms:issued": "2016-08-04T13:41+09:00",
      "dcterms:modified": "2017-05-23T14:28+09:00",
      "description": "Coordinate Plus App provided by Toshiba Corporation fails to verify SSL server certificates.\r\n\r\nGaku Taniguchi of RiskFinder,inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html",
      "sec:cpe": {
        "#text": "cpe:/a:toshiba:coordinate_plus",
        "@product": "Coordinate Plus App",
        "@vendor": "TOSHIBA",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "4.0",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "@version": "2.0"
        },
        {
          "@score": "4.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2016-000133",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN06920277/index.html",
          "@id": "JVN#06920277",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4840",
          "@id": "CVE-2016-4840",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2016-4840",
          "@id": "CVE-2016-4840",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Coordinate Plus App fails to verify SSL server certificates"
    }

    CVE-2023-29984 (GCVE-0-2023-29984)

    Vulnerability from nvd – Published: 2023-07-11 00:00 – Updated: 2024-11-08 16:24
    VLAI
    Summary
    Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-08 16:12 UTC
    CWE
    • n/a
    Impacted products
    Vendor Product Version
    brother_industries mfc-j960dwn_firmware Affected: d
        cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:*
    Create a notification for this product.
    fujifilm docuprint_p115_w Affected: 1.11
        cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:*
    Create a notification for this product.
    toshiba e-studio_301dn_302dnf Affected: 0
        cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T14:21:44.141Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.brother.com/g/s/security/en/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mfc-j960dwn_firmware",
                "vendor": "brother_industries",
                "versions": [
                  {
                    "status": "affected",
                    "version": "d"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "docuprint_p115_w",
                "vendor": "fujifilm",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.11"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "e-studio_301dn_302dnf",
                "vendor": "toshiba",
                "versions": [
                  {
                    "status": "affected",
                    "version": "0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-29984",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-08T16:12:21.247572Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-08T16:24:26.583Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T00:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
            },
            {
              "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
            },
            {
              "url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
            },
            {
              "url": "https://support.brother.com/g/s/security/en/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-29984",
        "datePublished": "2023-07-11T00:00:00.000Z",
        "dateReserved": "2023-04-07T00:00:00.000Z",
        "dateUpdated": "2024-11-08T16:24:26.583Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30421 (GCVE-0-2022-30421)

    Vulnerability from nvd – Published: 2023-01-31 00:00 – Updated: 2025-03-27 18:39
    VLAI
    Summary
    Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-27 18:38 UTC
    CWE
    • n/a
    • CWE-287 - Improper Authentication
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T06:48:36.170Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://global.gmarket.co.kr/item?goodscode=741668527"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ebay.com/itm/274246695791"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-30421",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-27T18:38:47.687758Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-287",
                    "description": "CWE-287 Improper Authentication",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-27T18:39:20.271Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-01-31T00:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "http://global.gmarket.co.kr/item?goodscode=741668527"
            },
            {
              "url": "https://www.ebay.com/itm/274246695791"
            },
            {
              "url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
            },
            {
              "url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-30421",
        "datePublished": "2023-01-31T00:00:00.000Z",
        "dateReserved": "2022-05-09T00:00:00.000Z",
        "dateUpdated": "2025-03-27T18:39:20.271Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2012-4981 (GCVE-0-2012-4981)

    Vulnerability from nvd – Published: 2020-01-23 14:25 – Updated: 2024-08-06 20:50
    VLAI
    Summary
    Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T20:50:18.312Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/55643"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-23T14:25:37.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.securityfocus.com/bid/55643"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2012-4981",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.securityfocus.com/bid/55643",
                  "refsource": "MISC",
                  "url": "http://www.securityfocus.com/bid/55643"
                },
                {
                  "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800",
                  "refsource": "MISC",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2012-4981",
        "datePublished": "2020-01-23T14:25:37.000Z",
        "dateReserved": "2012-09-19T00:00:00.000Z",
        "dateUpdated": "2024-08-06T20:50:18.312Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2012-4980 (GCVE-0-2012-4980)

    Vulnerability from nvd – Published: 2019-12-27 20:21 – Updated: 2024-08-06 20:50
    VLAI
    Summary
    Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/55644 vdb-entryx_refsource_BID
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    Date Public
    2012-09-21 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T20:50:18.515Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "55644",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/55644"
              },
              {
                "name": "78801",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2012-09-21T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-12-27T20:21:46.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "55644",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/55644"
            },
            {
              "name": "78801",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2012-4980",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "55644",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/55644"
                },
                {
                  "name": "78801",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2012-4980",
        "datePublished": "2019-12-27T20:21:46.000Z",
        "dateReserved": "2012-09-19T00:00:00.000Z",
        "dateUpdated": "2024-08-06T20:50:18.515Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-2162 (GCVE-0-2017-2162)

    Vulnerability from nvd – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
    VLAI
    Summary
    FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser.
    Severity
    No CVSS data available.
    CWE
    • Configures default credentials
    References
    URL Tags
    http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091 third-party-advisoryx_refsource_JVNDB
    https://jvn.jp/en/jp/JVN81820501/index.html third-party-advisoryx_refsource_JVN
    http://www.toshiba-personalstorage.net/news/20170… x_refsource_CONFIRM
    Date Public
    2017-05-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:48:03.557Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVNDB-2017-000091",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
              },
              {
                "name": "JVN#81820501",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN81820501/index.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00.02 and earlier"
                }
              ]
            },
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V2.00.04 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2017-05-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Configures default credentials",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-22T15:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVNDB-2017-000091",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
            },
            {
              "name": "JVN#81820501",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN81820501/index.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2017-2162",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.00.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V2.00.04 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba Corporation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Configures default credentials"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVNDB-2017-000091",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
                },
                {
                  "name": "JVN#81820501",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN81820501/index.html"
                },
                {
                  "name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
                  "refsource": "CONFIRM",
                  "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2017-2162",
        "datePublished": "2017-05-22T16:00:00.000Z",
        "dateReserved": "2016-12-01T00:00:00.000Z",
        "dateUpdated": "2024-08-05T13:48:03.557Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-2161 (GCVE-0-2017-2161)

    Vulnerability from nvd – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
    VLAI
    Summary
    FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
    Severity
    No CVSS data available.
    CWE
    • Fails to restrict access
    References
    URL Tags
    http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-0… third-party-advisoryx_refsource_JVNDB
    https://jvn.jp/en/jp/JVN46372675/index.html third-party-advisoryx_refsource_JVN
    http://www.toshiba-personalstorage.net/news/20170… x_refsource_CONFIRM
    Date Public
    2017-05-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:48:03.496Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVNDB-2017-000090",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
              },
              {
                "name": "JVN#46372675",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN46372675/index.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00.02 and earlier"
                }
              ]
            },
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V2.00.04 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2017-05-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Fails to restrict access",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-22T15:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVNDB-2017-000090",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
            },
            {
              "name": "JVN#46372675",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN46372675/index.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2017-2161",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.00.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V2.00.04 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba Corporation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Fails to restrict access"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVNDB-2017-000090",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
                },
                {
                  "name": "JVN#46372675",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN46372675/index.html"
                },
                {
                  "name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
                  "refsource": "CONFIRM",
                  "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2017-2161",
        "datePublished": "2017-05-22T16:00:00.000Z",
        "dateReserved": "2016-12-01T00:00:00.000Z",
        "dateUpdated": "2024-08-05T13:48:03.496Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2016-4863 (GCVE-0-2016-4863)

    Vulnerability from nvd – Published: 2017-05-22 16:00 – Updated: 2024-08-06 00:46
    VLAI
    Summary
    The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when "Internet pass-thru Mode" is enabled, which allows attackers with access to STA side LAN can obtain files or data.
    Severity
    No CVSS data available.
    CWE
    • Lack of authentication mechanism
    References
    URL Tags
    http://www.securityfocus.com/bid/93479 vdb-entryx_refsource_BID
    https://jvn.jp/en/jp/JVN39619137/index.html third-party-advisoryx_refsource_JVN
    http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168 third-party-advisoryx_refsource_JVNDB
    Date Public
    2016-10-07 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T00:46:38.522Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "93479",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/93479"
              },
              {
                "name": "JVN#39619137",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN39619137/index.html"
              },
              {
                "name": "JVNDB-2016-000168",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "FlashAir SD-WD/WC series Class 6 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.00.04 and later"
                }
              ]
            },
            {
              "product": "FlashAir SD-WD/WC series Class 10 model W-02",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 2.00.02 and later"
                }
              ]
            },
            {
              "product": "FlashAir SD-WE series Class 10 model W-03",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            },
            {
              "product": "FlashAir Class 6 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.00.04 and later"
                }
              ]
            },
            {
              "product": "FlashAir II Class 10 model W-02 series",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 2.00.02 and later"
                }
              ]
            },
            {
              "product": "FlashAir III Class 10 model W-03 series",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            },
            {
              "product": "FlashAir Class 6 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.00.04 and later"
                }
              ]
            },
            {
              "product": "FlashAir W-02 series Class 10 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 2.00.02 and later"
                }
              ]
            },
            {
              "product": "FlashAir W-03 series Class 10 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            }
          ],
          "datePublic": "2016-10-07T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Lack of authentication mechanism",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-23T09:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "93479",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/93479"
            },
            {
              "name": "JVN#39619137",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN39619137/index.html"
            },
            {
              "name": "JVNDB-2016-000168",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2016-4863",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "FlashAir SD-WD/WC series Class 6 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 1.00.04 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir SD-WD/WC series Class 10 model W-02",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 2.00.02 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir SD-WE series Class 10 model W-03",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all firmware versions"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir Class 6 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 1.00.04 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir II Class 10 model W-02 series",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 2.00.02 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir III Class 10 model W-03 series",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all firmware versions"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir Class 6 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 1.00.04 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir W-02 series Class 10 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 2.00.02 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir W-03 series Class 10 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all firmware versions"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Lack of authentication mechanism"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "93479",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/93479"
                },
                {
                  "name": "JVN#39619137",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN39619137/index.html"
                },
                {
                  "name": "JVNDB-2016-000168",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2016-4863",
        "datePublished": "2017-05-22T16:00:00.000Z",
        "dateReserved": "2016-05-17T00:00:00.000Z",
        "dateUpdated": "2024-08-06T00:46:38.522Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-2149 (GCVE-0-2017-2149)

    Vulnerability from nvd – Published: 2017-04-28 16:00 – Updated: 2024-08-05 13:48
    VLAI
    Summary
    Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
    Severity
    No CVSS data available.
    CWE
    • Untrusted search path vulnerability
    References
    URL Tags
    http://jvn.jp/en/jp/JVN05340816/index.html third-party-advisoryx_refsource_JVN
    http://www.toshiba-personalstorage.net/news/20170… x_refsource_MISC
    http://www.securityfocus.com/bid/97697 vdb-entryx_refsource_BID
    Date Public
    2017-04-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:48:03.535Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVN#05340816",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/en/jp/JVN05340816/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
              },
              {
                "name": "97697",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/97697"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.00.03 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.0.2 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00.01"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V2.00.03 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.00.04 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.02 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.00.06 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2017-04-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Untrusted search path vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-01T09:57:02.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVN#05340816",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "http://jvn.jp/en/jp/JVN05340816/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
            },
            {
              "name": "97697",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/97697"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2017-2149",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.00.03 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.0.2 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.00.01"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V2.00.03 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.00.04 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.00.06 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba Corporation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Untrusted search path vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVN#05340816",
                  "refsource": "JVN",
                  "url": "http://jvn.jp/en/jp/JVN05340816/index.html"
                },
                {
                  "name": "http://www.toshiba-personalstorage.net/news/20170414.htm",
                  "refsource": "MISC",
                  "url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
                },
                {
                  "name": "97697",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/97697"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2017-2149",
        "datePublished": "2017-04-28T16:00:00.000Z",
        "dateReserved": "2016-12-01T00:00:00.000Z",
        "dateUpdated": "2024-08-05T13:48:03.535Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2016-4840 (GCVE-0-2016-4840)

    Vulnerability from nvd – Published: 2017-04-21 14:00 – Updated: 2024-08-06 00:39
    VLAI
    Summary
    Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/92314 vdb-entryx_refsource_BID
    http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-0… third-party-advisoryx_refsource_JVNDB
    http://jvn.jp/en/jp/JVN06920277/index.html third-party-advisoryx_refsource_JVN
    Date Public
    2016-08-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T00:39:26.328Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "92314",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/92314"
              },
              {
                "name": "JVNDB-2016-000133",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
              },
              {
                "name": "JVN#06920277",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/en/jp/JVN06920277/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2016-08-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-04-21T13:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "92314",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/92314"
            },
            {
              "name": "JVNDB-2016-000133",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
            },
            {
              "name": "JVN#06920277",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "http://jvn.jp/en/jp/JVN06920277/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2016-4840",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "92314",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/92314"
                },
                {
                  "name": "JVNDB-2016-000133",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
                },
                {
                  "name": "JVN#06920277",
                  "refsource": "JVN",
                  "url": "http://jvn.jp/en/jp/JVN06920277/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2016-4840",
        "datePublished": "2017-04-21T14:00:00.000Z",
        "dateReserved": "2016-05-17T00:00:00.000Z",
        "dateUpdated": "2024-08-06T00:39:26.328Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-4876 (GCVE-0-2014-4876)

    Vulnerability from nvd – Published: 2015-12-31 02:00 – Updated: 2024-08-06 11:27
    VLAI
    Summary
    Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    https://www.kb.cert.org/vuls/id/924506 third-party-advisoryx_refsource_CERT-VN
    https://www.kb.cert.org/vuls/id/JLAD-9X4TDL x_refsource_CONFIRM
    Date Public
    2015-06-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T11:27:36.878Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "VU#924506",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "https://www.kb.cert.org/vuls/id/924506"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2015-06-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2015-12-31T04:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "VU#924506",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "https://www.kb.cert.org/vuls/id/924506"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2014-4876",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "VU#924506",
                  "refsource": "CERT-VN",
                  "url": "https://www.kb.cert.org/vuls/id/924506"
                },
                {
                  "name": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL",
                  "refsource": "CONFIRM",
                  "url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2014-4876",
        "datePublished": "2015-12-31T02:00:00.000Z",
        "dateReserved": "2014-07-10T00:00:00.000Z",
        "dateUpdated": "2024-08-06T11:27:36.878Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-4875 (GCVE-0-2014-4875)

    Vulnerability from nvd – Published: 2015-06-24 10:00 – Updated: 2024-08-06 11:27
    VLAI
    Summary
    CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.kb.cert.org/vuls/id/301788 third-party-advisoryx_refsource_CERT-VN
    http://www.kb.cert.org/vuls/id/JLAD-9X4SPN x_refsource_CONFIRM
    Date Public
    2015-06-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T11:27:36.993Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "VU#301788",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/301788"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2015-06-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2015-06-24T05:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "VU#301788",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/301788"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2014-4875",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "VU#301788",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/301788"
                },
                {
                  "name": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN",
                  "refsource": "CONFIRM",
                  "url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2014-4875",
        "datePublished": "2015-06-24T10:00:00.000Z",
        "dateReserved": "2014-07-10T00:00:00.000Z",
        "dateUpdated": "2024-08-06T11:27:36.993Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2015-0884 (GCVE-0-2015-0884)

    Vulnerability from nvd – Published: 2015-02-28 02:00 – Updated: 2024-08-06 04:26
    VLAI
    Summary
    Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2015-02-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T04:26:11.427Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
              },
              {
                "name": "1031825",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1031825"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
              },
              {
                "name": "VU#632140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/632140"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/vu/JVNVU99205169/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2015-02-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2015-03-19T15:57:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
            },
            {
              "name": "1031825",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1031825"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
            },
            {
              "name": "VU#632140",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/632140"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://jvn.jp/vu/JVNVU99205169/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2015-0884",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.support.toshiba.com/sscontent?contentId=4007187",
                  "refsource": "CONFIRM",
                  "url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
                },
                {
                  "name": "1031825",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1031825"
                },
                {
                  "name": "http://www.support.toshiba.com/sscontent?contentId=4007185",
                  "refsource": "CONFIRM",
                  "url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
                },
                {
                  "name": "VU#632140",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/632140"
                },
                {
                  "name": "http://jvn.jp/vu/JVNVU99205169/index.html",
                  "refsource": "MISC",
                  "url": "http://jvn.jp/vu/JVNVU99205169/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2015-0884",
        "datePublished": "2015-02-28T02:00:00.000Z",
        "dateReserved": "2015-01-08T00:00:00.000Z",
        "dateUpdated": "2024-08-06T04:26:11.427Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-29984 (GCVE-0-2023-29984)

    Vulnerability from cvelistv5 – Published: 2023-07-11 00:00 – Updated: 2024-11-08 16:24
    VLAI
    Summary
    Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-08 16:12 UTC
    CWE
    • n/a
    Impacted products
    Vendor Product Version
    brother_industries mfc-j960dwn_firmware Affected: d
        cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:*
    Create a notification for this product.
    fujifilm docuprint_p115_w Affected: 1.11
        cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:*
    Create a notification for this product.
    toshiba e-studio_301dn_302dnf Affected: 0
        cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T14:21:44.141Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.brother.com/g/s/security/en/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mfc-j960dwn_firmware",
                "vendor": "brother_industries",
                "versions": [
                  {
                    "status": "affected",
                    "version": "d"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "docuprint_p115_w",
                "vendor": "fujifilm",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.11"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "e-studio_301dn_302dnf",
                "vendor": "toshiba",
                "versions": [
                  {
                    "status": "affected",
                    "version": "0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-29984",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-08T16:12:21.247572Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-08T16:24:26.583Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T00:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
            },
            {
              "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
            },
            {
              "url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
            },
            {
              "url": "https://support.brother.com/g/s/security/en/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-29984",
        "datePublished": "2023-07-11T00:00:00.000Z",
        "dateReserved": "2023-04-07T00:00:00.000Z",
        "dateUpdated": "2024-11-08T16:24:26.583Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30421 (GCVE-0-2022-30421)

    Vulnerability from cvelistv5 – Published: 2023-01-31 00:00 – Updated: 2025-03-27 18:39
    VLAI
    Summary
    Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-27 18:38 UTC
    CWE
    • n/a
    • CWE-287 - Improper Authentication
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T06:48:36.170Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://global.gmarket.co.kr/item?goodscode=741668527"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ebay.com/itm/274246695791"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-30421",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-27T18:38:47.687758Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-287",
                    "description": "CWE-287 Improper Authentication",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-27T18:39:20.271Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-01-31T00:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "http://global.gmarket.co.kr/item?goodscode=741668527"
            },
            {
              "url": "https://www.ebay.com/itm/274246695791"
            },
            {
              "url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
            },
            {
              "url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-30421",
        "datePublished": "2023-01-31T00:00:00.000Z",
        "dateReserved": "2022-05-09T00:00:00.000Z",
        "dateUpdated": "2025-03-27T18:39:20.271Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2012-4981 (GCVE-0-2012-4981)

    Vulnerability from cvelistv5 – Published: 2020-01-23 14:25 – Updated: 2024-08-06 20:50
    VLAI
    Summary
    Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T20:50:18.312Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/55643"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-01-23T14:25:37.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.securityfocus.com/bid/55643"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2012-4981",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.securityfocus.com/bid/55643",
                  "refsource": "MISC",
                  "url": "http://www.securityfocus.com/bid/55643"
                },
                {
                  "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800",
                  "refsource": "MISC",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2012-4981",
        "datePublished": "2020-01-23T14:25:37.000Z",
        "dateReserved": "2012-09-19T00:00:00.000Z",
        "dateUpdated": "2024-08-06T20:50:18.312Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2012-4980 (GCVE-0-2012-4980)

    Vulnerability from cvelistv5 – Published: 2019-12-27 20:21 – Updated: 2024-08-06 20:50
    VLAI
    Summary
    Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/55644 vdb-entryx_refsource_BID
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    Date Public
    2012-09-21 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T20:50:18.515Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "55644",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/55644"
              },
              {
                "name": "78801",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2012-09-21T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-12-27T20:21:46.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "55644",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/55644"
            },
            {
              "name": "78801",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2012-4980",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "55644",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/55644"
                },
                {
                  "name": "78801",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2012-4980",
        "datePublished": "2019-12-27T20:21:46.000Z",
        "dateReserved": "2012-09-19T00:00:00.000Z",
        "dateUpdated": "2024-08-06T20:50:18.515Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2016-4863 (GCVE-0-2016-4863)

    Vulnerability from cvelistv5 – Published: 2017-05-22 16:00 – Updated: 2024-08-06 00:46
    VLAI
    Summary
    The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when "Internet pass-thru Mode" is enabled, which allows attackers with access to STA side LAN can obtain files or data.
    Severity
    No CVSS data available.
    CWE
    • Lack of authentication mechanism
    References
    URL Tags
    http://www.securityfocus.com/bid/93479 vdb-entryx_refsource_BID
    https://jvn.jp/en/jp/JVN39619137/index.html third-party-advisoryx_refsource_JVN
    http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168 third-party-advisoryx_refsource_JVNDB
    Date Public
    2016-10-07 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T00:46:38.522Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "93479",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/93479"
              },
              {
                "name": "JVN#39619137",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN39619137/index.html"
              },
              {
                "name": "JVNDB-2016-000168",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "FlashAir SD-WD/WC series Class 6 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.00.04 and later"
                }
              ]
            },
            {
              "product": "FlashAir SD-WD/WC series Class 10 model W-02",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 2.00.02 and later"
                }
              ]
            },
            {
              "product": "FlashAir SD-WE series Class 10 model W-03",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            },
            {
              "product": "FlashAir Class 6 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.00.04 and later"
                }
              ]
            },
            {
              "product": "FlashAir II Class 10 model W-02 series",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 2.00.02 and later"
                }
              ]
            },
            {
              "product": "FlashAir III Class 10 model W-03 series",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            },
            {
              "product": "FlashAir Class 6 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.00.04 and later"
                }
              ]
            },
            {
              "product": "FlashAir W-02 series Class 10 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 2.00.02 and later"
                }
              ]
            },
            {
              "product": "FlashAir W-03 series Class 10 model",
              "vendor": "Toshiba",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            }
          ],
          "datePublic": "2016-10-07T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Lack of authentication mechanism",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-23T09:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "93479",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/93479"
            },
            {
              "name": "JVN#39619137",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN39619137/index.html"
            },
            {
              "name": "JVNDB-2016-000168",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2016-4863",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "FlashAir SD-WD/WC series Class 6 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 1.00.04 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir SD-WD/WC series Class 10 model W-02",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 2.00.02 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir SD-WE series Class 10 model W-03",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all firmware versions"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir Class 6 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 1.00.04 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir II Class 10 model W-02 series",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 2.00.02 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir III Class 10 model W-03 series",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all firmware versions"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir Class 6 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 1.00.04 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir W-02 series Class 10 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "firmware version 2.00.02 and later"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAir W-03 series Class 10 model",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all firmware versions"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Lack of authentication mechanism"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "93479",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/93479"
                },
                {
                  "name": "JVN#39619137",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN39619137/index.html"
                },
                {
                  "name": "JVNDB-2016-000168",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2016-4863",
        "datePublished": "2017-05-22T16:00:00.000Z",
        "dateReserved": "2016-05-17T00:00:00.000Z",
        "dateUpdated": "2024-08-06T00:46:38.522Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-2161 (GCVE-0-2017-2161)

    Vulnerability from cvelistv5 – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
    VLAI
    Summary
    FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
    Severity
    No CVSS data available.
    CWE
    • Fails to restrict access
    References
    URL Tags
    http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-0… third-party-advisoryx_refsource_JVNDB
    https://jvn.jp/en/jp/JVN46372675/index.html third-party-advisoryx_refsource_JVN
    http://www.toshiba-personalstorage.net/news/20170… x_refsource_CONFIRM
    Date Public
    2017-05-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:48:03.496Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVNDB-2017-000090",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
              },
              {
                "name": "JVN#46372675",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN46372675/index.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00.02 and earlier"
                }
              ]
            },
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V2.00.04 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2017-05-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Fails to restrict access",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-22T15:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVNDB-2017-000090",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
            },
            {
              "name": "JVN#46372675",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN46372675/index.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2017-2161",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.00.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V2.00.04 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba Corporation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Fails to restrict access"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVNDB-2017-000090",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
                },
                {
                  "name": "JVN#46372675",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN46372675/index.html"
                },
                {
                  "name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
                  "refsource": "CONFIRM",
                  "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2017-2161",
        "datePublished": "2017-05-22T16:00:00.000Z",
        "dateReserved": "2016-12-01T00:00:00.000Z",
        "dateUpdated": "2024-08-05T13:48:03.496Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-2162 (GCVE-0-2017-2162)

    Vulnerability from cvelistv5 – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
    VLAI
    Summary
    FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser.
    Severity
    No CVSS data available.
    CWE
    • Configures default credentials
    References
    URL Tags
    http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091 third-party-advisoryx_refsource_JVNDB
    https://jvn.jp/en/jp/JVN81820501/index.html third-party-advisoryx_refsource_JVN
    http://www.toshiba-personalstorage.net/news/20170… x_refsource_CONFIRM
    Date Public
    2017-05-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:48:03.557Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVNDB-2017-000091",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
              },
              {
                "name": "JVN#81820501",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN81820501/index.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00.02 and earlier"
                }
              ]
            },
            {
              "product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V2.00.04 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2017-05-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Configures default credentials",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-22T15:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVNDB-2017-000091",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
            },
            {
              "name": "JVN#81820501",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN81820501/index.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2017-2162",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.00.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V2.00.04 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba Corporation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Configures default credentials"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVNDB-2017-000091",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
                },
                {
                  "name": "JVN#81820501",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN81820501/index.html"
                },
                {
                  "name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
                  "refsource": "CONFIRM",
                  "url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2017-2162",
        "datePublished": "2017-05-22T16:00:00.000Z",
        "dateReserved": "2016-12-01T00:00:00.000Z",
        "dateUpdated": "2024-08-05T13:48:03.557Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-2149 (GCVE-0-2017-2149)

    Vulnerability from cvelistv5 – Published: 2017-04-28 16:00 – Updated: 2024-08-05 13:48
    VLAI
    Summary
    Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
    Severity
    No CVSS data available.
    CWE
    • Untrusted search path vulnerability
    References
    URL Tags
    http://jvn.jp/en/jp/JVN05340816/index.html third-party-advisoryx_refsource_JVN
    http://www.toshiba-personalstorage.net/news/20170… x_refsource_MISC
    http://www.securityfocus.com/bid/97697 vdb-entryx_refsource_BID
    Date Public
    2017-04-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:48:03.535Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVN#05340816",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/en/jp/JVN05340816/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
              },
              {
                "name": "97697",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/97697"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.00.03 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.0.2 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00.01"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V2.00.03 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.00.04 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.02 and earlier"
                }
              ]
            },
            {
              "product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
              "vendor": "Toshiba Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.00.06 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2017-04-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Untrusted search path vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-05-01T09:57:02.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVN#05340816",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "http://jvn.jp/en/jp/JVN05340816/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
            },
            {
              "name": "97697",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/97697"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2017-2149",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.00.03 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.0.2 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V3.00.01"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V2.00.03 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.00.04 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "V1.00.06 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Toshiba Corporation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Untrusted search path vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVN#05340816",
                  "refsource": "JVN",
                  "url": "http://jvn.jp/en/jp/JVN05340816/index.html"
                },
                {
                  "name": "http://www.toshiba-personalstorage.net/news/20170414.htm",
                  "refsource": "MISC",
                  "url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
                },
                {
                  "name": "97697",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/97697"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2017-2149",
        "datePublished": "2017-04-28T16:00:00.000Z",
        "dateReserved": "2016-12-01T00:00:00.000Z",
        "dateUpdated": "2024-08-05T13:48:03.535Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2016-4840 (GCVE-0-2016-4840)

    Vulnerability from cvelistv5 – Published: 2017-04-21 14:00 – Updated: 2024-08-06 00:39
    VLAI
    Summary
    Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/92314 vdb-entryx_refsource_BID
    http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-0… third-party-advisoryx_refsource_JVNDB
    http://jvn.jp/en/jp/JVN06920277/index.html third-party-advisoryx_refsource_JVN
    Date Public
    2016-08-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T00:39:26.328Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "92314",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/92314"
              },
              {
                "name": "JVNDB-2016-000133",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVNDB",
                  "x_transferred"
                ],
                "url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
              },
              {
                "name": "JVN#06920277",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/en/jp/JVN06920277/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2016-08-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-04-21T13:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "92314",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/92314"
            },
            {
              "name": "JVNDB-2016-000133",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVNDB"
              ],
              "url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
            },
            {
              "name": "JVN#06920277",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "http://jvn.jp/en/jp/JVN06920277/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2016-4840",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "92314",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/92314"
                },
                {
                  "name": "JVNDB-2016-000133",
                  "refsource": "JVNDB",
                  "url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
                },
                {
                  "name": "JVN#06920277",
                  "refsource": "JVN",
                  "url": "http://jvn.jp/en/jp/JVN06920277/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2016-4840",
        "datePublished": "2017-04-21T14:00:00.000Z",
        "dateReserved": "2016-05-17T00:00:00.000Z",
        "dateUpdated": "2024-08-06T00:39:26.328Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-4876 (GCVE-0-2014-4876)

    Vulnerability from cvelistv5 – Published: 2015-12-31 02:00 – Updated: 2024-08-06 11:27
    VLAI
    Summary
    Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    https://www.kb.cert.org/vuls/id/924506 third-party-advisoryx_refsource_CERT-VN
    https://www.kb.cert.org/vuls/id/JLAD-9X4TDL x_refsource_CONFIRM
    Date Public
    2015-06-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T11:27:36.878Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "VU#924506",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "https://www.kb.cert.org/vuls/id/924506"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2015-06-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2015-12-31T04:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "VU#924506",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "https://www.kb.cert.org/vuls/id/924506"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2014-4876",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "VU#924506",
                  "refsource": "CERT-VN",
                  "url": "https://www.kb.cert.org/vuls/id/924506"
                },
                {
                  "name": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL",
                  "refsource": "CONFIRM",
                  "url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2014-4876",
        "datePublished": "2015-12-31T02:00:00.000Z",
        "dateReserved": "2014-07-10T00:00:00.000Z",
        "dateUpdated": "2024-08-06T11:27:36.878Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-4875 (GCVE-0-2014-4875)

    Vulnerability from cvelistv5 – Published: 2015-06-24 10:00 – Updated: 2024-08-06 11:27
    VLAI
    Summary
    CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.kb.cert.org/vuls/id/301788 third-party-advisoryx_refsource_CERT-VN
    http://www.kb.cert.org/vuls/id/JLAD-9X4SPN x_refsource_CONFIRM
    Date Public
    2015-06-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T11:27:36.993Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "VU#301788",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/301788"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2015-06-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2015-06-24T05:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "VU#301788",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/301788"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2014-4875",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "VU#301788",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/301788"
                },
                {
                  "name": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN",
                  "refsource": "CONFIRM",
                  "url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2014-4875",
        "datePublished": "2015-06-24T10:00:00.000Z",
        "dateReserved": "2014-07-10T00:00:00.000Z",
        "dateUpdated": "2024-08-06T11:27:36.993Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2015-0884 (GCVE-0-2015-0884)

    Vulnerability from cvelistv5 – Published: 2015-02-28 02:00 – Updated: 2024-08-06 04:26
    VLAI
    Summary
    Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2015-02-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T04:26:11.427Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
              },
              {
                "name": "1031825",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1031825"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
              },
              {
                "name": "VU#632140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/632140"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/vu/JVNVU99205169/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2015-02-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2015-03-19T15:57:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
            },
            {
              "name": "1031825",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1031825"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
            },
            {
              "name": "VU#632140",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/632140"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://jvn.jp/vu/JVNVU99205169/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2015-0884",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.support.toshiba.com/sscontent?contentId=4007187",
                  "refsource": "CONFIRM",
                  "url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
                },
                {
                  "name": "1031825",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1031825"
                },
                {
                  "name": "http://www.support.toshiba.com/sscontent?contentId=4007185",
                  "refsource": "CONFIRM",
                  "url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
                },
                {
                  "name": "VU#632140",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/632140"
                },
                {
                  "name": "http://jvn.jp/vu/JVNVU99205169/index.html",
                  "refsource": "MISC",
                  "url": "http://jvn.jp/vu/JVNVU99205169/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2015-0884",
        "datePublished": "2015-02-28T02:00:00.000Z",
        "dateReserved": "2015-01-08T00:00:00.000Z",
        "dateUpdated": "2024-08-06T04:26:11.427Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }