CRITICAL🇵🇱 Wersja polska

CVE-2024-47406

CVSS 9.1v3.1pub. 2024-10-25upd. 2024-11-05

Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.

🤖 AI Analysis
How it works

The firmware of vulnerable MFP devices contains a flaw in the HTTP authentication handling mechanism (CWE-288, CWE-306 — missing or improper identity verification). An attacker can send a specially crafted HTTP request that will be treated by the device as authenticated, thereby bypassing the required login procedure. The attack can be performed remotely without possessing any authentication credentials.

Impact

Attackers gain unauthorized access to MFP device resources and functions, which may result in disclosure of confidential data (e.g., scanned documents, configuration data) and disruption of device availability.

Mitigation & patch

Apply patches available from the manufacturer according to references (https://www.toshibatec.com/information/20241025_01.html and https://global.sharp/products/copier/info/info_security_2024-10.html). Additionally, until updates are deployed, it is recommended to restrict network access to MFP device administrative panels using firewall or network segmentation.

Who is affected

Toshibatec E-Studio908, E-Studio1058, and E-Studio1208 (along with appropriate firmware). A complete list of affected models and firmware versions is available in manufacturer references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Sharp Bp 30c25

    HW
    Sharp
    all versions
  • Sharp Bp 30c25 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 30c25t

    HW
    Sharp
    all versions
  • Sharp Bp 30c25t Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 30c25y

    HW
    Sharp
    all versions
  • Sharp Bp 30c25y Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 30c25z

    HW
    Sharp
    all versions
  • Sharp Bp 30c25z Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 50c26

    HW
    Sharp
    all versions
  • Sharp Bp 50c26 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 50c31

    HW
    Sharp
    all versions
  • Sharp Bp 50c31 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 50c36

    HW
    Sharp
    all versions
  • Sharp Bp 50c36 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 50c45

    HW
    Sharp
    all versions
  • Sharp Bp 50c45 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 50c55

    HW
    Sharp
    all versions
  • Sharp Bp 50c55 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 50c65

    HW
    Sharp
    all versions
  • Sharp Bp 50c65 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 55c26

    HW
    Sharp
    all versions
  • Sharp Bp 55c26 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 60c31

    HW
    Sharp
    all versions
  • Sharp Bp 60c31 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 60c36

    HW
    Sharp
    all versions
  • Sharp Bp 60c36 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 60c45

    HW
    Sharp
    all versions
  • Sharp Bp 60c45 Firmware

    OS
    Sharp
    all versions
  • Sharp Bp 70c31

    HW
    Sharp
    all versions
  • Sharp Bp 70c31 Firmware

    OS
    Sharp
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-45796CRITICAL9.1PL ✓same product

Command injection w SHARP MFP — zdalne wykonanie poleceń przez nw_interface.html

CVE-2024-47549HIGH7.4same product

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination...

CVE-2024-47801HIGH7.4same product

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cros...

CVE-2024-42420HIGH7.5same product

Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of ...

CVE-2024-43424HIGH7.5same product

Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnera...