Hardcoded password used to encrypt logs and use of weak cipher
Vulnerability Description
All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27160
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.
References
More from Toshiba Tec Corporation
View All →Affected Vendor
Toshiba Tec Corporation
View all reports →