Lucene search

K
cveMitreCVE-2023-34259
HistoryNov 03, 2023 - 4:15 a.m.

CVE-2023-34259

2023-11-0304:15:20
CWE-22
mitre
web.nvd.nist.gov
47
cve-2023
kyocera
taskalfa 4053ci
printers
directory traversal
arbitrary files
filesystem
incomplete fix

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.025

Percentile

90.4%

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

Affected configurations

Nvd
Node
kyocerad-copia253mf_plus_firmwareRange2vg_s000.002.561
AND
kyocerad-copia253mf_plusMatch-
VendorProductVersionCPE
kyocerad-copia253mf_plus_firmware*cpe:2.3:o:kyocera:d-copia253mf_plus_firmware:*:*:*:*:*:*:*:*
kyocerad-copia253mf_plus-cpe:2.3:h:kyocera:d-copia253mf_plus:-:*:*:*:*:*:*:*

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.025

Percentile

90.4%