cvelist/2024/36xxx/CVE-2024-36248.json

117 lines
4.4 KiB
JSON
Raw Normal View History

2024-05-22 10:00:34 +00:00
{
2024-11-26 08:00:34 +00:00
"data_version": "4.0",
2024-05-22 10:00:34 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-36248",
2024-11-26 08:00:34 +00:00
"ASSIGNER": "vultures@jpcert.or.jp",
"STATE": "PUBLIC"
2024-05-22 10:00:34 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2024-11-26 08:00:34 +00:00
"value": "API keys for some cloud services are hardcoded in the \"main\" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Use of hard-coded credentials",
"cweId": "CWE-798"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Sharp Corporation",
"product": {
"product_data": [
{
"product_name": "Multiple MFPs (multifunction printers)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "See the information provided by Sharp Corporation listed under [References]"
}
]
}
}
]
}
},
{
"vendor_name": "Toshiba Tec Corporation",
"product": {
"product_data": [
{
"product_name": "Multiple MFPs (multifunction printers)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "See the information provided by Toshiba Tec Corporation listed under [References]"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://global.sharp/products/copier/info/info_security_2024-05.html",
"refsource": "MISC",
"name": "https://global.sharp/products/copier/info/info_security_2024-05.html"
},
{
"url": "https://jp.sharp/business/print/information/info_security_2024-05.html",
"refsource": "MISC",
"name": "https://jp.sharp/business/print/information/info_security_2024-05.html"
},
{
"url": "https://www.toshibatec.com/information/20240531_02.html",
"refsource": "MISC",
"name": "https://www.toshibatec.com/information/20240531_02.html"
},
{
"url": "https://www.toshibatec.co.jp/information/20240531_02.html",
"refsource": "MISC",
"name": "https://www.toshibatec.co.jp/information/20240531_02.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93051062/",
"refsource": "MISC",
"name": "https://jvn.jp/en/vu/JVNVU93051062/"
},
{
"url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html",
"refsource": "MISC",
"name": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html"
}
]
},
"impact": {
"cvss": [
{
"version": "3.1",
"baseSeverity": "CRITICAL",
"baseScore": 9.1,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
2024-05-22 10:00:34 +00:00
}
]
}
}