Search
Find a vulnerability
Search criteria
47 vulnerabilities by TOSHIBA
JVNDB-2026-020742
Vulnerability from jvndb - Published: 2026-06-26 00:52 - Updated:2026-06-26 00:52
Severity
Summary
Generic IO & Memory Access driver for TOSHIBA and Dynabook PCs exposes its IOCTL with insufficient access control
Details
Generic IO & Memory Access driver is part of a utility to configure BIOS/Supervisor passwords from within Windows. This driver is installed on PCs provided by TOSHIBA CORPORATION and Dynabook Inc. between 2009 and 2016.
The driver contains the following vulnerability.
- Exposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-56129
- The CVSS assessment above assumes that a user with no administrative privilege accesses physical memory.
References
| Type | URL | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-020742.html",
"dc:date": "2026-06-26T09:52+09:00",
"dcterms:issued": "2026-06-26T09:52+09:00",
"dcterms:modified": "2026-06-26T09:52+09:00",
"description": "Generic IO \u0026 Memory Access driver is part of a utility to configure BIOS/Supervisor passwords from within Windows. This driver is installed on PCs provided by TOSHIBA CORPORATION and Dynabook Inc. between 2009 and 2016.\r\nThe driver contains the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/782.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eExposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-56129\u003c/li\u003e\u003cul\u003e\u003cli\u003eThe CVSS assessment above assumes that a user with no administrative privilege accesses physical memory.\u003c/li\u003e\u003c/ul\u003e\u003c/ul\u003eAkshit Yadav (valium) reported this vulnerability to the developer. The developer reported the case to JPCERT/CC to notify users of the solution through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-020742.html",
"sec:cpe": {
"#text": "cpe:/a:toshiba:generic_io_and_memory_access_driver",
"@product": "Generic IO \u0026 Memory Access driver",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
"sec:cvss": {
"@score": "5.5",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-020742",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU91051826/index.html",
"@id": "JVNVU#91051826",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-56129",
"@id": "CVE-2026-56129",
"@source": "CVE"
},
{
"#text": "https://cwe.mitre.org/data/definitions/782.html",
"@id": "CWE-782",
"@title": "Exposed IOCTL with Insufficient Access Control(CWE-782)"
}
],
"title": "Generic IO \u0026 Memory Access driver for TOSHIBA and Dynabook PCs exposes its IOCTL with insufficient access control"
}
JVNDB-2017-000091
Vulnerability from jvndb - Published: 2017-05-16 06:46 - Updated:2017-12-21 10:16
Severity
Summary
FlashAir do not set credential information in PhotoShare
Details
FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the image data in a certain folder with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare.
When enabling PhotoShare with a mobile application (either for Android or iOS), the application prompts a user to set credentials. But when enabling PhotoShare with web browsers, the wireless LAN connection for PhotoShare cannot be enabled, and default credentials are set to the other wireless network configured to the device. As a result, a remote attacker with access to the wireless LAN may obtain image data by using default credentials (CWE-284).
Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000091.html",
"dc:date": "2017-12-21T19:16+09:00",
"dcterms:issued": "2017-05-16T15:46+09:00",
"dcterms:modified": "2017-12-21T19:16+09:00",
"description": "FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the image data in a certain folder with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare.\r\n\r\nWhen enabling PhotoShare with a mobile application (either for Android or iOS), the application prompts a user to set credentials. But when enabling PhotoShare with web browsers, the wireless LAN connection for PhotoShare cannot be enabled, and default credentials are set to the other wireless network configured to the device. As a result, a remote attacker with access to the wireless LAN may obtain image data by using default credentials (CWE-284).\r\n\r\nTakayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000091.html",
"sec:cpe": {
"#text": "cpe:/a:toshiba:flashair",
"@product": "FlashAir",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "3.3",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:N/C:P/I:N/A:N",
"@version": "2.0"
},
{
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000091",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN81820501/index.html",
"@id": "JVN#81820501",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2162",
"@id": "CVE-2017-2162",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2162",
"@id": "CVE-2017-2162",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "FlashAir do not set credential information in PhotoShare"
}
JVNDB-2017-000090
Vulnerability from jvndb - Published: 2017-05-16 06:34 - Updated:2017-12-21 10:13
Severity
Summary
FlashAir fails to restrict access permissions in PhotoShare
Details
FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the selected data with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare.
FlashAir fails to restrict access permissions (CWE-425) in PhotoShare.
Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html",
"dc:date": "2017-12-21T19:13+09:00",
"dcterms:issued": "2017-05-16T15:34+09:00",
"dcterms:modified": "2017-12-21T19:13+09:00",
"description": "FlashAir by Toshiba Corporation is an SDHC memory card which provides wireless LAN access functions. FlashAir PhotoShare function enables to share the selected data with other users as it switches the original wireless LAN connection set by FlashAir default to the wireless LAN connection for PhotoShare.\r\n\r\nFlashAir fails to restrict access permissions (CWE-425) in PhotoShare.\r\n\r\nTakayoshi Isayama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html",
"sec:cpe": {
"#text": "cpe:/a:toshiba:flashair",
"@product": "FlashAir",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "2.7",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:S/C:P/I:N/A:N",
"@version": "2.0"
},
{
"@score": "3.5",
"@severity": "Low",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000090",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN46372675/index.html",
"@id": "JVN#46372675",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2161",
"@id": "CVE-2017-2161",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2161",
"@id": "CVE-2017-2161",
"@source": "NVD"
},
{
"#text": "https://cwe.mitre.org/data/definitions/284.html",
"@id": "CWE-284",
"@title": "Improper Access Control(CWE-284)"
}
],
"title": "FlashAir fails to restrict access permissions in PhotoShare"
}
JVNDB-2017-000069
Vulnerability from jvndb - Published: 2017-04-14 05:09 - Updated:2017-12-21 08:50
Severity
Summary
Multiple installers of Toshiba memory card related software may insecurely load Dynamic Link Libraries
Details
Multiple installers of Toshiba memory card related software contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).
Yuji Tounai of NTT Communications Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000069.html",
"dc:date": "2017-12-21T17:50+09:00",
"dcterms:issued": "2017-04-14T14:09+09:00",
"dcterms:modified": "2017-12-21T17:50+09:00",
"description": "Multiple installers of Toshiba memory card related software contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).\r\n\r\nYuji Tounai of NTT Communications Corporation reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000069.html",
"sec:cpe": [
{
"#text": "cpe:/a:toshiba:nfc_sdhc_%2F_sdxc_memory_card_software_updatetool",
"@product": "SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
{
"#text": "cpe:/a:toshiba:sdhc_memory_card_with_transferjet_firmware_updatetool",
"@product": "SDHC Memory Card with embedded TransferJet functionality Software Update tool",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
{
"#text": "cpe:/a:toshiba:sdhc_memory_card_with_transferjet_setting_software",
"@product": "SDHC Memory Card with embedded TransferJet functionality Configuration Software",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
{
"#text": "cpe:/a:toshiba:wlan_sdhc_memory_card_flashair_setting_software",
"@product": "SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
{
"#text": "cpe:/a:toshiba:wlan_sdhc_memory_card_flashair_setting_software_updatetool",
"@product": "SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool",
"@vendor": "TOSHIBA",
"@version": "2.2"
}
],
"sec:cvss": [
{
"@score": "6.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "7.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000069",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN05340816/index.html",
"@id": "JVN#05340816",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2149",
"@id": "CVE-2017-2149",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2149",
"@id": "CVE-2017-2149",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Multiple installers of Toshiba memory card related software may insecurely load Dynamic Link Libraries"
}
JVNDB-2016-000168
Vulnerability from jvndb - Published: 2016-10-12 01:03 - Updated:2017-11-27 08:04
Severity
Summary
Toshiba FlashAir does not require authentication in "Internet pass-thru Mode"
Details
FlashAir by Toshiba Corporation is a SDHC memory card which provides "Internet pass-thru Mode", allowing devices to access the internet while connecting to FlashAir. When configured in "Internet pass-thru Mode", FlashAir acts both as a station and as an access point.
When "Internet pass-thru Mode" is enabled, FlashAir does not require authentication on accepting a connection from STA (station) side LAN.
Tsukada Nobuhisa of Seasoft reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000168.html",
"dc:date": "2017-11-27T17:04+09:00",
"dcterms:issued": "2016-10-12T10:03+09:00",
"dcterms:modified": "2017-11-27T17:04+09:00",
"description": "FlashAir by Toshiba Corporation is a SDHC memory card which provides \"Internet pass-thru Mode\", allowing devices to access the internet while connecting to FlashAir. When configured in \"Internet pass-thru Mode\", FlashAir acts both as a station and as an access point.\r\nWhen \"Internet pass-thru Mode\" is enabled, FlashAir does not require authentication on accepting a connection from STA (station) side LAN.\r\n\r\nTsukada Nobuhisa of Seasoft reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000168.html",
"sec:cpe": {
"#text": "cpe:/a:toshiba:flashair",
"@product": "FlashAir",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "5.4",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:A/AC:M/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "5.0",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2016-000168",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN39619137/index.html",
"@id": "JVN#39619137",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4863",
"@id": "CVE-2016-4863",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2016-4863",
"@id": "CVE-2016-4863",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-264",
"@title": "Permissions(CWE-264)"
}
],
"title": "Toshiba FlashAir does not require authentication in \"Internet pass-thru Mode\""
}
JVNDB-2016-000133
Vulnerability from jvndb - Published: 2016-08-04 04:41 - Updated:2017-05-23 05:28
Severity
Summary
Coordinate Plus App fails to verify SSL server certificates
Details
Coordinate Plus App provided by Toshiba Corporation fails to verify SSL server certificates.
Gaku Taniguchi of RiskFinder,inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html",
"dc:date": "2017-05-23T14:28+09:00",
"dcterms:issued": "2016-08-04T13:41+09:00",
"dcterms:modified": "2017-05-23T14:28+09:00",
"description": "Coordinate Plus App provided by Toshiba Corporation fails to verify SSL server certificates.\r\n\r\nGaku Taniguchi of RiskFinder,inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html",
"sec:cpe": {
"#text": "cpe:/a:toshiba:coordinate_plus",
"@product": "Coordinate Plus App",
"@vendor": "TOSHIBA",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "4.0",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
"@version": "2.0"
},
{
"@score": "4.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2016-000133",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN06920277/index.html",
"@id": "JVN#06920277",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4840",
"@id": "CVE-2016-4840",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2016-4840",
"@id": "CVE-2016-4840",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Coordinate Plus App fails to verify SSL server certificates"
}
CVE-2023-29984 (GCVE-0-2023-29984)
Vulnerability from nvd – Published: 2023-07-11 00:00 – Updated: 2024-11-08 16:24
VLAI
EPSS
VEX
Summary
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
Severity
No CVSS data available.
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-08 16:12 UTC
CWE
- n/a
Assigner
References
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| brother_industries | mfc-j960dwn_firmware |
Affected:
d
cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:* |
|
| fujifilm | docuprint_p115_w |
Affected:
1.11
cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:* |
|
| toshiba | e-studio_301dn_302dnf |
Affected:
0
cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T14:21:44.141Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.brother.com/g/s/security/en/"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mfc-j960dwn_firmware",
"vendor": "brother_industries",
"versions": [
{
"status": "affected",
"version": "d"
}
]
},
{
"cpes": [
"cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "docuprint_p115_w",
"vendor": "fujifilm",
"versions": [
{
"status": "affected",
"version": "1.11"
}
]
},
{
"cpes": [
"cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "e-studio_301dn_302dnf",
"vendor": "toshiba",
"versions": [
{
"status": "affected",
"version": "0"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-29984",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-08T16:12:21.247572Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-08T16:24:26.583Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-08-07T00:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
},
{
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
},
{
"url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
},
{
"url": "https://support.brother.com/g/s/security/en/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2023-29984",
"datePublished": "2023-07-11T00:00:00.000Z",
"dateReserved": "2023-04-07T00:00:00.000Z",
"dateUpdated": "2024-11-08T16:24:26.583Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-30421 (GCVE-0-2022-30421)
Vulnerability from nvd – Published: 2023-01-31 00:00 – Updated: 2025-03-27 18:39
VLAI
EPSS
VEX
Summary
Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
Severity
7.8 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-03-27 18:38 UTC
CWE
- n/a
- CWE-287 - Improper Authentication
Assigner
References
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T06:48:36.170Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "http://global.gmarket.co.kr/item?goodscode=741668527"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.ebay.com/itm/274246695791"
},
{
"tags": [
"x_transferred"
],
"url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-30421",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-27T18:38:47.687758Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-27T18:39:20.271Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-01-31T00:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "http://global.gmarket.co.kr/item?goodscode=741668527"
},
{
"url": "https://www.ebay.com/itm/274246695791"
},
{
"url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
},
{
"url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-30421",
"datePublished": "2023-01-31T00:00:00.000Z",
"dateReserved": "2022-05-09T00:00:00.000Z",
"dateUpdated": "2025-03-27T18:39:20.271Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2012-4981 (GCVE-0-2012-4981)
Vulnerability from nvd – Published: 2020-01-23 14:25 – Updated: 2024-08-06 20:50
VLAI
EPSS
VEX
Summary
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/55643 | x_refsource_MISC |
| https://exchange.xforce.ibmcloud.com/vulnerabilit… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T20:50:18.312Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/55643"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2020-01-23T14:25:37.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "http://www.securityfocus.com/bid/55643"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2012-4981",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "http://www.securityfocus.com/bid/55643",
"refsource": "MISC",
"url": "http://www.securityfocus.com/bid/55643"
},
{
"name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800",
"refsource": "MISC",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2012-4981",
"datePublished": "2020-01-23T14:25:37.000Z",
"dateReserved": "2012-09-19T00:00:00.000Z",
"dateUpdated": "2024-08-06T20:50:18.312Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2012-4980 (GCVE-0-2012-4980)
Vulnerability from nvd – Published: 2019-12-27 20:21 – Updated: 2024-08-06 20:50
VLAI
EPSS
VEX
Summary
Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/55644 | vdb-entryx_refsource_BID |
| https://exchange.xforce.ibmcloud.com/vulnerabilit… | vdb-entryx_refsource_XF |
Date Public
2012-09-21 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T20:50:18.515Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "55644",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/55644"
},
{
"name": "78801",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2012-09-21T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2019-12-27T20:21:46.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "55644",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/55644"
},
{
"name": "78801",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2012-4980",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "55644",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/55644"
},
{
"name": "78801",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2012-4980",
"datePublished": "2019-12-27T20:21:46.000Z",
"dateReserved": "2012-09-19T00:00:00.000Z",
"dateUpdated": "2024-08-06T20:50:18.515Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2162 (GCVE-0-2017-2162)
Vulnerability from nvd – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser.
Severity
No CVSS data available.
CWE
- Configures default credentials
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091 | third-party-advisoryx_refsource_JVNDB |
| https://jvn.jp/en/jp/JVN81820501/index.html | third-party-advisoryx_refsource_JVN |
| http://www.toshiba-personalstorage.net/news/20170… | x_refsource_CONFIRM |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) |
Affected:
V3.00.02 and earlier
|
|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) |
Affected:
V2.00.04 and earlier
|
Date Public
2017-05-16 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.557Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2017-000091",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
},
{
"name": "JVN#81820501",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN81820501/index.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.00.02 and earlier"
}
]
},
{
"product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V2.00.04 and earlier"
}
]
}
],
"datePublic": "2017-05-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Configures default credentials",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-22T15:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2017-000091",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
},
{
"name": "JVN#81820501",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN81820501/index.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2162",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"version": {
"version_data": [
{
"version_value": "V3.00.02 and earlier"
}
]
}
},
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"version": {
"version_data": [
{
"version_value": "V2.00.04 and earlier"
}
]
}
}
]
},
"vendor_name": "Toshiba Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Configures default credentials"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2017-000091",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
},
{
"name": "JVN#81820501",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN81820501/index.html"
},
{
"name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
"refsource": "CONFIRM",
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2162",
"datePublished": "2017-05-22T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.557Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2161 (GCVE-0-2017-2161)
Vulnerability from nvd – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
Severity
No CVSS data available.
CWE
- Fails to restrict access
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-0… | third-party-advisoryx_refsource_JVNDB |
| https://jvn.jp/en/jp/JVN46372675/index.html | third-party-advisoryx_refsource_JVN |
| http://www.toshiba-personalstorage.net/news/20170… | x_refsource_CONFIRM |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) |
Affected:
V3.00.02 and earlier
|
|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) |
Affected:
V2.00.04 and earlier
|
Date Public
2017-05-16 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.496Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2017-000090",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
},
{
"name": "JVN#46372675",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN46372675/index.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.00.02 and earlier"
}
]
},
{
"product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V2.00.04 and earlier"
}
]
}
],
"datePublic": "2017-05-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Fails to restrict access",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-22T15:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2017-000090",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
},
{
"name": "JVN#46372675",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN46372675/index.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2161",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"version": {
"version_data": [
{
"version_value": "V3.00.02 and earlier"
}
]
}
},
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"version": {
"version_data": [
{
"version_value": "V2.00.04 and earlier"
}
]
}
}
]
},
"vendor_name": "Toshiba Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Fails to restrict access"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2017-000090",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
},
{
"name": "JVN#46372675",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN46372675/index.html"
},
{
"name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
"refsource": "CONFIRM",
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2161",
"datePublished": "2017-05-22T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.496Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-4863 (GCVE-0-2016-4863)
Vulnerability from nvd – Published: 2017-05-22 16:00 – Updated: 2024-08-06 00:46
VLAI
EPSS
VEX
Summary
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when "Internet pass-thru Mode" is enabled, which allows attackers with access to STA side LAN can obtain files or data.
Severity
No CVSS data available.
CWE
- Lack of authentication mechanism
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/93479 | vdb-entryx_refsource_BID |
| https://jvn.jp/en/jp/JVN39619137/index.html | third-party-advisoryx_refsource_JVN |
| http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168 | third-party-advisoryx_refsource_JVNDB |
Impacted products
8 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba | FlashAir SD-WD/WC series Class 6 model |
Affected:
firmware version 1.00.04 and later
|
|
| Toshiba | FlashAir SD-WD/WC series Class 10 model W-02 |
Affected:
firmware version 2.00.02 and later
|
|
| Toshiba | FlashAir SD-WE series Class 10 model W-03 |
Affected:
all firmware versions
|
|
| Toshiba | FlashAir Class 6 model |
Affected:
firmware version 1.00.04 and later
|
|
| Toshiba | FlashAir II Class 10 model W-02 series |
Affected:
firmware version 2.00.02 and later
|
|
| Toshiba | FlashAir III Class 10 model W-03 series |
Affected:
all firmware versions
|
|
| Toshiba | FlashAir W-02 series Class 10 model |
Affected:
firmware version 2.00.02 and later
|
|
| Toshiba | FlashAir W-03 series Class 10 model |
Affected:
all firmware versions
|
Date Public
2016-10-07 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T00:46:38.522Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "93479",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/93479"
},
{
"name": "JVN#39619137",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN39619137/index.html"
},
{
"name": "JVNDB-2016-000168",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "FlashAir SD-WD/WC series Class 6 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 1.00.04 and later"
}
]
},
{
"product": "FlashAir SD-WD/WC series Class 10 model W-02",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 2.00.02 and later"
}
]
},
{
"product": "FlashAir SD-WE series Class 10 model W-03",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "all firmware versions"
}
]
},
{
"product": "FlashAir Class 6 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 1.00.04 and later"
}
]
},
{
"product": "FlashAir II Class 10 model W-02 series",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 2.00.02 and later"
}
]
},
{
"product": "FlashAir III Class 10 model W-03 series",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "all firmware versions"
}
]
},
{
"product": "FlashAir Class 6 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 1.00.04 and later"
}
]
},
{
"product": "FlashAir W-02 series Class 10 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 2.00.02 and later"
}
]
},
{
"product": "FlashAir W-03 series Class 10 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "all firmware versions"
}
]
}
],
"datePublic": "2016-10-07T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Lack of authentication mechanism",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-23T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "93479",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/93479"
},
{
"name": "JVN#39619137",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN39619137/index.html"
},
{
"name": "JVNDB-2016-000168",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-4863",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "FlashAir SD-WD/WC series Class 6 model",
"version": {
"version_data": [
{
"version_value": "firmware version 1.00.04 and later"
}
]
}
},
{
"product_name": "FlashAir SD-WD/WC series Class 10 model W-02",
"version": {
"version_data": [
{
"version_value": "firmware version 2.00.02 and later"
}
]
}
},
{
"product_name": "FlashAir SD-WE series Class 10 model W-03",
"version": {
"version_data": [
{
"version_value": "all firmware versions"
}
]
}
},
{
"product_name": "FlashAir Class 6 model",
"version": {
"version_data": [
{
"version_value": "firmware version 1.00.04 and later"
}
]
}
},
{
"product_name": "FlashAir II Class 10 model W-02 series",
"version": {
"version_data": [
{
"version_value": "firmware version 2.00.02 and later"
}
]
}
},
{
"product_name": "FlashAir III Class 10 model W-03 series",
"version": {
"version_data": [
{
"version_value": "all firmware versions"
}
]
}
},
{
"product_name": "FlashAir Class 6 model",
"version": {
"version_data": [
{
"version_value": "firmware version 1.00.04 and later"
}
]
}
},
{
"product_name": "FlashAir W-02 series Class 10 model",
"version": {
"version_data": [
{
"version_value": "firmware version 2.00.02 and later"
}
]
}
},
{
"product_name": "FlashAir W-03 series Class 10 model",
"version": {
"version_data": [
{
"version_value": "all firmware versions"
}
]
}
}
]
},
"vendor_name": "Toshiba"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Lack of authentication mechanism"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "93479",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/93479"
},
{
"name": "JVN#39619137",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN39619137/index.html"
},
{
"name": "JVNDB-2016-000168",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-4863",
"datePublished": "2017-05-22T16:00:00.000Z",
"dateReserved": "2016-05-17T00:00:00.000Z",
"dateUpdated": "2024-08-06T00:46:38.522Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2149 (GCVE-0-2017-2149)
Vulnerability from nvd – Published: 2017-04-28 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvn.jp/en/jp/JVN05340816/index.html | third-party-advisoryx_refsource_JVN |
| http://www.toshiba-personalstorage.net/news/20170… | x_refsource_MISC |
| http://www.securityfocus.com/bid/97697 | vdb-entryx_refsource_BID |
Impacted products
7 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba Corporation | Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool |
Affected:
V1.00.03 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software |
Affected:
V3.0.2 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series<W-03>) |
Affected:
V3.00.01
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series<W-02>) |
Affected:
V2.00.03 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series) |
Affected:
V1.00.04 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software |
Affected:
V1.02 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool |
Affected:
V1.00.06 and earlier
|
Date Public
2017-04-28 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.535Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVN#05340816",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN05340816/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
},
{
"name": "97697",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/97697"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.00.03 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.0.2 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.00.01"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V2.00.03 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.00.04 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.02 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.00.06 and earlier"
}
]
}
],
"datePublic": "2017-04-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-01T09:57:02.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVN#05340816",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN05340816/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
},
{
"name": "97697",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/97697"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2149",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
"version": {
"version_data": [
{
"version_value": "V1.00.03 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
"version": {
"version_data": [
{
"version_value": "V3.0.2 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
"version": {
"version_data": [
{
"version_value": "V3.00.01"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
"version": {
"version_data": [
{
"version_value": "V2.00.03 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
"version": {
"version_data": [
{
"version_value": "V1.00.04 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
"version": {
"version_data": [
{
"version_value": "V1.02 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
"version": {
"version_data": [
{
"version_value": "V1.00.06 and earlier"
}
]
}
}
]
},
"vendor_name": "Toshiba Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVN#05340816",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN05340816/index.html"
},
{
"name": "http://www.toshiba-personalstorage.net/news/20170414.htm",
"refsource": "MISC",
"url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
},
{
"name": "97697",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/97697"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2149",
"datePublished": "2017-04-28T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.535Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-4840 (GCVE-0-2016-4840)
Vulnerability from nvd – Published: 2017-04-21 14:00 – Updated: 2024-08-06 00:39
VLAI
EPSS
VEX
Summary
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/92314 | vdb-entryx_refsource_BID |
| http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-0… | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN06920277/index.html | third-party-advisoryx_refsource_JVN |
Date Public
2016-08-04 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T00:39:26.328Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "92314",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/92314"
},
{
"name": "JVNDB-2016-000133",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
},
{
"name": "JVN#06920277",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN06920277/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2016-08-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-04-21T13:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "92314",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/92314"
},
{
"name": "JVNDB-2016-000133",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
},
{
"name": "JVN#06920277",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN06920277/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-4840",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "92314",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/92314"
},
{
"name": "JVNDB-2016-000133",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
},
{
"name": "JVN#06920277",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN06920277/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-4840",
"datePublished": "2017-04-21T14:00:00.000Z",
"dateReserved": "2016-05-17T00:00:00.000Z",
"dateUpdated": "2024-08-06T00:39:26.328Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2014-4876 (GCVE-0-2014-4876)
Vulnerability from nvd – Published: 2015-12-31 02:00 – Updated: 2024-08-06 11:27
VLAI
EPSS
VEX
Summary
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.kb.cert.org/vuls/id/924506 | third-party-advisoryx_refsource_CERT-VN |
| https://www.kb.cert.org/vuls/id/JLAD-9X4TDL | x_refsource_CONFIRM |
Date Public
2015-06-08 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T11:27:36.878Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "VU#924506",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN",
"x_transferred"
],
"url": "https://www.kb.cert.org/vuls/id/924506"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2015-06-08T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2015-12-31T04:57:01.000Z",
"orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"shortName": "certcc"
},
"references": [
{
"name": "VU#924506",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN"
],
"url": "https://www.kb.cert.org/vuls/id/924506"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cert@cert.org",
"ID": "CVE-2014-4876",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "VU#924506",
"refsource": "CERT-VN",
"url": "https://www.kb.cert.org/vuls/id/924506"
},
{
"name": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL",
"refsource": "CONFIRM",
"url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"assignerShortName": "certcc",
"cveId": "CVE-2014-4876",
"datePublished": "2015-12-31T02:00:00.000Z",
"dateReserved": "2014-07-10T00:00:00.000Z",
"dateUpdated": "2024-08-06T11:27:36.878Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2014-4875 (GCVE-0-2014-4875)
Vulnerability from nvd – Published: 2015-06-24 10:00 – Updated: 2024-08-06 11:27
VLAI
EPSS
VEX
Summary
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.kb.cert.org/vuls/id/301788 | third-party-advisoryx_refsource_CERT-VN |
| http://www.kb.cert.org/vuls/id/JLAD-9X4SPN | x_refsource_CONFIRM |
Date Public
2015-06-08 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T11:27:36.993Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "VU#301788",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN",
"x_transferred"
],
"url": "http://www.kb.cert.org/vuls/id/301788"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2015-06-08T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2015-06-24T05:57:01.000Z",
"orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"shortName": "certcc"
},
"references": [
{
"name": "VU#301788",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN"
],
"url": "http://www.kb.cert.org/vuls/id/301788"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cert@cert.org",
"ID": "CVE-2014-4875",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "VU#301788",
"refsource": "CERT-VN",
"url": "http://www.kb.cert.org/vuls/id/301788"
},
{
"name": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN",
"refsource": "CONFIRM",
"url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"assignerShortName": "certcc",
"cveId": "CVE-2014-4875",
"datePublished": "2015-06-24T10:00:00.000Z",
"dateReserved": "2014-07-10T00:00:00.000Z",
"dateUpdated": "2024-08-06T11:27:36.993Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2015-0884 (GCVE-0-2015-0884)
Vulnerability from nvd – Published: 2015-02-28 02:00 – Updated: 2024-08-06 04:26
VLAI
EPSS
VEX
Summary
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
5 references
| URL | Tags |
|---|---|
| http://www.support.toshiba.com/sscontent?contentI… | x_refsource_CONFIRM |
| http://www.securitytracker.com/id/1031825 | vdb-entryx_refsource_SECTRACK |
| http://www.support.toshiba.com/sscontent?contentI… | x_refsource_CONFIRM |
| http://www.kb.cert.org/vuls/id/632140 | third-party-advisoryx_refsource_CERT-VN |
| http://jvn.jp/vu/JVNVU99205169/index.html | x_refsource_MISC |
Date Public
2015-02-26 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T04:26:11.427Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
},
{
"name": "1031825",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id/1031825"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
},
{
"name": "VU#632140",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN",
"x_transferred"
],
"url": "http://www.kb.cert.org/vuls/id/632140"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://jvn.jp/vu/JVNVU99205169/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2015-02-26T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2015-03-19T15:57:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
},
{
"name": "1031825",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id/1031825"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
},
{
"name": "VU#632140",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN"
],
"url": "http://www.kb.cert.org/vuls/id/632140"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://jvn.jp/vu/JVNVU99205169/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2015-0884",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "http://www.support.toshiba.com/sscontent?contentId=4007187",
"refsource": "CONFIRM",
"url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
},
{
"name": "1031825",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id/1031825"
},
{
"name": "http://www.support.toshiba.com/sscontent?contentId=4007185",
"refsource": "CONFIRM",
"url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
},
{
"name": "VU#632140",
"refsource": "CERT-VN",
"url": "http://www.kb.cert.org/vuls/id/632140"
},
{
"name": "http://jvn.jp/vu/JVNVU99205169/index.html",
"refsource": "MISC",
"url": "http://jvn.jp/vu/JVNVU99205169/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2015-0884",
"datePublished": "2015-02-28T02:00:00.000Z",
"dateReserved": "2015-01-08T00:00:00.000Z",
"dateUpdated": "2024-08-06T04:26:11.427Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-29984 (GCVE-0-2023-29984)
Vulnerability from cvelistv5 – Published: 2023-07-11 00:00 – Updated: 2024-11-08 16:24
VLAI
EPSS
VEX
Summary
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
Severity
No CVSS data available.
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-08 16:12 UTC
CWE
- n/a
Assigner
References
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| brother_industries | mfc-j960dwn_firmware |
Affected:
d
cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:* |
|
| fujifilm | docuprint_p115_w |
Affected:
1.11
cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:* |
|
| toshiba | e-studio_301dn_302dnf |
Affected:
0
cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T14:21:44.141Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.brother.com/g/s/security/en/"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:o:brother_industries:mfc-j960dwn_firmware:d:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mfc-j960dwn_firmware",
"vendor": "brother_industries",
"versions": [
{
"status": "affected",
"version": "d"
}
]
},
{
"cpes": [
"cpe:2.3:h:fujifilm:docuprint_p115_w:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "docuprint_p115_w",
"vendor": "fujifilm",
"versions": [
{
"status": "affected",
"version": "1.11"
}
]
},
{
"cpes": [
"cpe:2.3:a:toshiba:e-studio_301dn_302dnf:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "e-studio_301dn_302dnf",
"vendor": "toshiba",
"versions": [
{
"status": "affected",
"version": "0"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-29984",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-08T16:12:21.247572Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-08T16:24:26.583Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-08-07T00:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://jvn.jp/en/vu/JVNVU93767756/index.html"
},
{
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.html"
},
{
"url": "https://support.brother.com/g/b/faqend.aspx?c=us\u0026lang=en\u0026prod=group2\u0026faqid=faq00100793_000"
},
{
"url": "https://support.brother.com/g/s/security/en/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2023-29984",
"datePublished": "2023-07-11T00:00:00.000Z",
"dateReserved": "2023-04-07T00:00:00.000Z",
"dateUpdated": "2024-11-08T16:24:26.583Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-30421 (GCVE-0-2022-30421)
Vulnerability from cvelistv5 – Published: 2023-01-31 00:00 – Updated: 2025-03-27 18:39
VLAI
EPSS
VEX
Summary
Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
Severity
7.8 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-03-27 18:38 UTC
CWE
- n/a
- CWE-287 - Improper Authentication
Assigner
References
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T06:48:36.170Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "http://global.gmarket.co.kr/item?goodscode=741668527"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.ebay.com/itm/274246695791"
},
{
"tags": [
"x_transferred"
],
"url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-30421",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-27T18:38:47.687758Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-27T18:39:20.271Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-01-31T00:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "http://global.gmarket.co.kr/item?goodscode=741668527"
},
{
"url": "https://www.ebay.com/itm/274246695791"
},
{
"url": "http://global.11st.co.kr/glb/product/SellerProductDetail.tmall?method=getSellerProductDetail\u0026prdNo=1398327038"
},
{
"url": "https://github.com/bosslabdcu/Vulnerability-Reporting/security/advisories/GHSA-px7r-44vj-8h7m"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-30421",
"datePublished": "2023-01-31T00:00:00.000Z",
"dateReserved": "2022-05-09T00:00:00.000Z",
"dateUpdated": "2025-03-27T18:39:20.271Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2012-4981 (GCVE-0-2012-4981)
Vulnerability from cvelistv5 – Published: 2020-01-23 14:25 – Updated: 2024-08-06 20:50
VLAI
EPSS
VEX
Summary
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/55643 | x_refsource_MISC |
| https://exchange.xforce.ibmcloud.com/vulnerabilit… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T20:50:18.312Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/55643"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2020-01-23T14:25:37.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "http://www.securityfocus.com/bid/55643"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2012-4981",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability"
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "http://www.securityfocus.com/bid/55643",
"refsource": "MISC",
"url": "http://www.securityfocus.com/bid/55643"
},
{
"name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800",
"refsource": "MISC",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78800"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2012-4981",
"datePublished": "2020-01-23T14:25:37.000Z",
"dateReserved": "2012-09-19T00:00:00.000Z",
"dateUpdated": "2024-08-06T20:50:18.312Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2012-4980 (GCVE-0-2012-4980)
Vulnerability from cvelistv5 – Published: 2019-12-27 20:21 – Updated: 2024-08-06 20:50
VLAI
EPSS
VEX
Summary
Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/55644 | vdb-entryx_refsource_BID |
| https://exchange.xforce.ibmcloud.com/vulnerabilit… | vdb-entryx_refsource_XF |
Date Public
2012-09-21 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T20:50:18.515Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "55644",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/55644"
},
{
"name": "78801",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2012-09-21T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2019-12-27T20:21:46.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "55644",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/55644"
},
{
"name": "78801",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2012-4980",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "55644",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/55644"
},
{
"name": "78801",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78801"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2012-4980",
"datePublished": "2019-12-27T20:21:46.000Z",
"dateReserved": "2012-09-19T00:00:00.000Z",
"dateUpdated": "2024-08-06T20:50:18.515Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-4863 (GCVE-0-2016-4863)
Vulnerability from cvelistv5 – Published: 2017-05-22 16:00 – Updated: 2024-08-06 00:46
VLAI
EPSS
VEX
Summary
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when "Internet pass-thru Mode" is enabled, which allows attackers with access to STA side LAN can obtain files or data.
Severity
No CVSS data available.
CWE
- Lack of authentication mechanism
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/93479 | vdb-entryx_refsource_BID |
| https://jvn.jp/en/jp/JVN39619137/index.html | third-party-advisoryx_refsource_JVN |
| http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168 | third-party-advisoryx_refsource_JVNDB |
Impacted products
8 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba | FlashAir SD-WD/WC series Class 6 model |
Affected:
firmware version 1.00.04 and later
|
|
| Toshiba | FlashAir SD-WD/WC series Class 10 model W-02 |
Affected:
firmware version 2.00.02 and later
|
|
| Toshiba | FlashAir SD-WE series Class 10 model W-03 |
Affected:
all firmware versions
|
|
| Toshiba | FlashAir Class 6 model |
Affected:
firmware version 1.00.04 and later
|
|
| Toshiba | FlashAir II Class 10 model W-02 series |
Affected:
firmware version 2.00.02 and later
|
|
| Toshiba | FlashAir III Class 10 model W-03 series |
Affected:
all firmware versions
|
|
| Toshiba | FlashAir W-02 series Class 10 model |
Affected:
firmware version 2.00.02 and later
|
|
| Toshiba | FlashAir W-03 series Class 10 model |
Affected:
all firmware versions
|
Date Public
2016-10-07 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T00:46:38.522Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "93479",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/93479"
},
{
"name": "JVN#39619137",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN39619137/index.html"
},
{
"name": "JVNDB-2016-000168",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "FlashAir SD-WD/WC series Class 6 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 1.00.04 and later"
}
]
},
{
"product": "FlashAir SD-WD/WC series Class 10 model W-02",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 2.00.02 and later"
}
]
},
{
"product": "FlashAir SD-WE series Class 10 model W-03",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "all firmware versions"
}
]
},
{
"product": "FlashAir Class 6 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 1.00.04 and later"
}
]
},
{
"product": "FlashAir II Class 10 model W-02 series",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 2.00.02 and later"
}
]
},
{
"product": "FlashAir III Class 10 model W-03 series",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "all firmware versions"
}
]
},
{
"product": "FlashAir Class 6 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 1.00.04 and later"
}
]
},
{
"product": "FlashAir W-02 series Class 10 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "firmware version 2.00.02 and later"
}
]
},
{
"product": "FlashAir W-03 series Class 10 model",
"vendor": "Toshiba",
"versions": [
{
"status": "affected",
"version": "all firmware versions"
}
]
}
],
"datePublic": "2016-10-07T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Lack of authentication mechanism",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-23T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "93479",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/93479"
},
{
"name": "JVN#39619137",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN39619137/index.html"
},
{
"name": "JVNDB-2016-000168",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-4863",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "FlashAir SD-WD/WC series Class 6 model",
"version": {
"version_data": [
{
"version_value": "firmware version 1.00.04 and later"
}
]
}
},
{
"product_name": "FlashAir SD-WD/WC series Class 10 model W-02",
"version": {
"version_data": [
{
"version_value": "firmware version 2.00.02 and later"
}
]
}
},
{
"product_name": "FlashAir SD-WE series Class 10 model W-03",
"version": {
"version_data": [
{
"version_value": "all firmware versions"
}
]
}
},
{
"product_name": "FlashAir Class 6 model",
"version": {
"version_data": [
{
"version_value": "firmware version 1.00.04 and later"
}
]
}
},
{
"product_name": "FlashAir II Class 10 model W-02 series",
"version": {
"version_data": [
{
"version_value": "firmware version 2.00.02 and later"
}
]
}
},
{
"product_name": "FlashAir III Class 10 model W-03 series",
"version": {
"version_data": [
{
"version_value": "all firmware versions"
}
]
}
},
{
"product_name": "FlashAir Class 6 model",
"version": {
"version_data": [
{
"version_value": "firmware version 1.00.04 and later"
}
]
}
},
{
"product_name": "FlashAir W-02 series Class 10 model",
"version": {
"version_data": [
{
"version_value": "firmware version 2.00.02 and later"
}
]
}
},
{
"product_name": "FlashAir W-03 series Class 10 model",
"version": {
"version_data": [
{
"version_value": "all firmware versions"
}
]
}
}
]
},
"vendor_name": "Toshiba"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when \"Internet pass-thru Mode\" is enabled, which allows attackers with access to STA side LAN can obtain files or data."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Lack of authentication mechanism"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "93479",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/93479"
},
{
"name": "JVN#39619137",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN39619137/index.html"
},
{
"name": "JVNDB-2016-000168",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000168"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-4863",
"datePublished": "2017-05-22T16:00:00.000Z",
"dateReserved": "2016-05-17T00:00:00.000Z",
"dateUpdated": "2024-08-06T00:46:38.522Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2161 (GCVE-0-2017-2161)
Vulnerability from cvelistv5 – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
Severity
No CVSS data available.
CWE
- Fails to restrict access
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-0… | third-party-advisoryx_refsource_JVNDB |
| https://jvn.jp/en/jp/JVN46372675/index.html | third-party-advisoryx_refsource_JVN |
| http://www.toshiba-personalstorage.net/news/20170… | x_refsource_CONFIRM |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) |
Affected:
V3.00.02 and earlier
|
|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) |
Affected:
V2.00.04 and earlier
|
Date Public
2017-05-16 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.496Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2017-000090",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
},
{
"name": "JVN#46372675",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN46372675/index.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.00.02 and earlier"
}
]
},
{
"product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V2.00.04 and earlier"
}
]
}
],
"datePublic": "2017-05-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Fails to restrict access",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-22T15:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2017-000090",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
},
{
"name": "JVN#46372675",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN46372675/index.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2161",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"version": {
"version_data": [
{
"version_value": "V3.00.02 and earlier"
}
]
}
},
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"version": {
"version_data": [
{
"version_value": "V2.00.04 and earlier"
}
]
}
}
]
},
"vendor_name": "Toshiba Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Fails to restrict access"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2017-000090",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html"
},
{
"name": "JVN#46372675",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN46372675/index.html"
},
{
"name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
"refsource": "CONFIRM",
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2161",
"datePublished": "2017-05-22T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.496Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2162 (GCVE-0-2017-2162)
Vulnerability from cvelistv5 – Published: 2017-05-22 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser.
Severity
No CVSS data available.
CWE
- Configures default credentials
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091 | third-party-advisoryx_refsource_JVNDB |
| https://jvn.jp/en/jp/JVN81820501/index.html | third-party-advisoryx_refsource_JVN |
| http://www.toshiba-personalstorage.net/news/20170… | x_refsource_CONFIRM |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) |
Affected:
V3.00.02 and earlier
|
|
| Toshiba Corporation | FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) |
Affected:
V2.00.04 and earlier
|
Date Public
2017-05-16 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.557Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2017-000091",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
},
{
"name": "JVN#81820501",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN81820501/index.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.00.02 and earlier"
}
]
},
{
"product": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V2.00.04 and earlier"
}
]
}
],
"datePublic": "2017-05-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Configures default credentials",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-22T15:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2017-000091",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
},
{
"name": "JVN#81820501",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN81820501/index.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2162",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e)",
"version": {
"version_data": [
{
"version_value": "V3.00.02 and earlier"
}
]
}
},
{
"product_name": "FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e)",
"version": {
"version_data": [
{
"version_value": "V2.00.04 and earlier"
}
]
}
}
]
},
"vendor_name": "Toshiba Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "FlashAirTM SDHC Memory Card (SD-WE Series \u003cW-03\u003e) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series \u003cW-02\u003e) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Configures default credentials"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2017-000091",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2017-000091"
},
{
"name": "JVN#81820501",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN81820501/index.html"
},
{
"name": "http://www.toshiba-personalstorage.net/news/20170516a.htm",
"refsource": "CONFIRM",
"url": "http://www.toshiba-personalstorage.net/news/20170516a.htm"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2162",
"datePublished": "2017-05-22T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.557Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2149 (GCVE-0-2017-2149)
Vulnerability from cvelistv5 – Published: 2017-04-28 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvn.jp/en/jp/JVN05340816/index.html | third-party-advisoryx_refsource_JVN |
| http://www.toshiba-personalstorage.net/news/20170… | x_refsource_MISC |
| http://www.securityfocus.com/bid/97697 | vdb-entryx_refsource_BID |
Impacted products
7 products
| Vendor | Product | Version | |
|---|---|---|---|
| Toshiba Corporation | Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool |
Affected:
V1.00.03 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software |
Affected:
V3.0.2 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series<W-03>) |
Affected:
V3.00.01
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series<W-02>) |
Affected:
V2.00.03 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series) |
Affected:
V1.00.04 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software |
Affected:
V1.02 and earlier
|
|
| Toshiba Corporation | Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool |
Affected:
V1.00.06 and earlier
|
Date Public
2017-04-28 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.535Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVN#05340816",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN05340816/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
},
{
"name": "97697",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/97697"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.00.03 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.0.2 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V3.00.01"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V2.00.03 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.00.04 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.02 and earlier"
}
]
},
{
"product": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
"vendor": "Toshiba Corporation",
"versions": [
{
"status": "affected",
"version": "V1.00.06 and earlier"
}
]
}
],
"datePublic": "2017-04-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-05-01T09:57:02.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVN#05340816",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN05340816/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
},
{
"name": "97697",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/97697"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2149",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Installer for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool",
"version": {
"version_data": [
{
"version_value": "V1.00.03 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Configuration Software",
"version": {
"version_data": [
{
"version_value": "V3.0.2 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WE series\u003cW-03\u003e)",
"version": {
"version_data": [
{
"version_value": "V3.00.01"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WD/WC series\u003cW-02\u003e)",
"version": {
"version_data": [
{
"version_value": "V2.00.03 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded wireless LAN functionality FlashAirTM Software Update tool (SD-WB/WL series)",
"version": {
"version_data": [
{
"version_value": "V1.00.04 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Configuration Software",
"version": {
"version_data": [
{
"version_value": "V1.02 and earlier"
}
]
}
},
{
"product_name": "Installer for SDHC Memory Card with embedded TransferJetTM functionality Software Update tool",
"version": {
"version_data": [
{
"version_value": "V1.00.06 and earlier"
}
]
}
}
]
},
"vendor_name": "Toshiba Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series\u003cW-03\u003e) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series\u003cW-02\u003e) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVN#05340816",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN05340816/index.html"
},
{
"name": "http://www.toshiba-personalstorage.net/news/20170414.htm",
"refsource": "MISC",
"url": "http://www.toshiba-personalstorage.net/news/20170414.htm"
},
{
"name": "97697",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/97697"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2149",
"datePublished": "2017-04-28T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.535Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-4840 (GCVE-0-2016-4840)
Vulnerability from cvelistv5 – Published: 2017-04-21 14:00 – Updated: 2024-08-06 00:39
VLAI
EPSS
VEX
Summary
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/92314 | vdb-entryx_refsource_BID |
| http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-0… | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN06920277/index.html | third-party-advisoryx_refsource_JVN |
Date Public
2016-08-04 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T00:39:26.328Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "92314",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/92314"
},
{
"name": "JVNDB-2016-000133",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
},
{
"name": "JVN#06920277",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN06920277/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2016-08-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-04-21T13:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "92314",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/92314"
},
{
"name": "JVNDB-2016-000133",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
},
{
"name": "JVN#06920277",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN06920277/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-4840",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "92314",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/92314"
},
{
"name": "JVNDB-2016-000133",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000133.html"
},
{
"name": "JVN#06920277",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN06920277/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-4840",
"datePublished": "2017-04-21T14:00:00.000Z",
"dateReserved": "2016-05-17T00:00:00.000Z",
"dateUpdated": "2024-08-06T00:39:26.328Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2014-4876 (GCVE-0-2014-4876)
Vulnerability from cvelistv5 – Published: 2015-12-31 02:00 – Updated: 2024-08-06 11:27
VLAI
EPSS
VEX
Summary
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.kb.cert.org/vuls/id/924506 | third-party-advisoryx_refsource_CERT-VN |
| https://www.kb.cert.org/vuls/id/JLAD-9X4TDL | x_refsource_CONFIRM |
Date Public
2015-06-08 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T11:27:36.878Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "VU#924506",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN",
"x_transferred"
],
"url": "https://www.kb.cert.org/vuls/id/924506"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2015-06-08T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2015-12-31T04:57:01.000Z",
"orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"shortName": "certcc"
},
"references": [
{
"name": "VU#924506",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN"
],
"url": "https://www.kb.cert.org/vuls/id/924506"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cert@cert.org",
"ID": "CVE-2014-4876",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "VU#924506",
"refsource": "CERT-VN",
"url": "https://www.kb.cert.org/vuls/id/924506"
},
{
"name": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL",
"refsource": "CONFIRM",
"url": "https://www.kb.cert.org/vuls/id/JLAD-9X4TDL"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"assignerShortName": "certcc",
"cveId": "CVE-2014-4876",
"datePublished": "2015-12-31T02:00:00.000Z",
"dateReserved": "2014-07-10T00:00:00.000Z",
"dateUpdated": "2024-08-06T11:27:36.878Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2014-4875 (GCVE-0-2014-4875)
Vulnerability from cvelistv5 – Published: 2015-06-24 10:00 – Updated: 2024-08-06 11:27
VLAI
EPSS
VEX
Summary
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.kb.cert.org/vuls/id/301788 | third-party-advisoryx_refsource_CERT-VN |
| http://www.kb.cert.org/vuls/id/JLAD-9X4SPN | x_refsource_CONFIRM |
Date Public
2015-06-08 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T11:27:36.993Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "VU#301788",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN",
"x_transferred"
],
"url": "http://www.kb.cert.org/vuls/id/301788"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2015-06-08T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2015-06-24T05:57:01.000Z",
"orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"shortName": "certcc"
},
"references": [
{
"name": "VU#301788",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN"
],
"url": "http://www.kb.cert.org/vuls/id/301788"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cert@cert.org",
"ID": "CVE-2014-4875",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "VU#301788",
"refsource": "CERT-VN",
"url": "http://www.kb.cert.org/vuls/id/301788"
},
{
"name": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN",
"refsource": "CONFIRM",
"url": "http://www.kb.cert.org/vuls/id/JLAD-9X4SPN"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"assignerShortName": "certcc",
"cveId": "CVE-2014-4875",
"datePublished": "2015-06-24T10:00:00.000Z",
"dateReserved": "2014-07-10T00:00:00.000Z",
"dateUpdated": "2024-08-06T11:27:36.993Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2015-0884 (GCVE-0-2015-0884)
Vulnerability from cvelistv5 – Published: 2015-02-28 02:00 – Updated: 2024-08-06 04:26
VLAI
EPSS
VEX
Summary
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
5 references
| URL | Tags |
|---|---|
| http://www.support.toshiba.com/sscontent?contentI… | x_refsource_CONFIRM |
| http://www.securitytracker.com/id/1031825 | vdb-entryx_refsource_SECTRACK |
| http://www.support.toshiba.com/sscontent?contentI… | x_refsource_CONFIRM |
| http://www.kb.cert.org/vuls/id/632140 | third-party-advisoryx_refsource_CERT-VN |
| http://jvn.jp/vu/JVNVU99205169/index.html | x_refsource_MISC |
Date Public
2015-02-26 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T04:26:11.427Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
},
{
"name": "1031825",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id/1031825"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
},
{
"name": "VU#632140",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN",
"x_transferred"
],
"url": "http://www.kb.cert.org/vuls/id/632140"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://jvn.jp/vu/JVNVU99205169/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2015-02-26T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2015-03-19T15:57:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
},
{
"name": "1031825",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id/1031825"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
},
{
"name": "VU#632140",
"tags": [
"third-party-advisory",
"x_refsource_CERT-VN"
],
"url": "http://www.kb.cert.org/vuls/id/632140"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://jvn.jp/vu/JVNVU99205169/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2015-0884",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "http://www.support.toshiba.com/sscontent?contentId=4007187",
"refsource": "CONFIRM",
"url": "http://www.support.toshiba.com/sscontent?contentId=4007187"
},
{
"name": "1031825",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id/1031825"
},
{
"name": "http://www.support.toshiba.com/sscontent?contentId=4007185",
"refsource": "CONFIRM",
"url": "http://www.support.toshiba.com/sscontent?contentId=4007185"
},
{
"name": "VU#632140",
"refsource": "CERT-VN",
"url": "http://www.kb.cert.org/vuls/id/632140"
},
{
"name": "http://jvn.jp/vu/JVNVU99205169/index.html",
"refsource": "MISC",
"url": "http://jvn.jp/vu/JVNVU99205169/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2015-0884",
"datePublished": "2015-02-28T02:00:00.000Z",
"dateReserved": "2015-01-08T00:00:00.000Z",
"dateUpdated": "2024-08-06T04:26:11.427Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}