Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-34259
HistoryNov 03, 2023 - 12:00 a.m.

CVE-2023-34259

2023-11-0300:00:00
mitre
github.com
4
kyocera taskalfa 4053ci
directory traversal
arbitrary files
filesystem
incomplete fix

AI Score

5.3

Confidence

High

EPSS

0.025

Percentile

90.4%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:h:kyocera:taskalfa_4053ci:*:*:*:*:*:*:*:*"
    ],
    "vendor": "kyocera",
    "product": "taskalfa_4053ci",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "2VG_S000.002.561"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

5.3

Confidence

High

EPSS

0.025

Percentile

90.4%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-34259