CVE-2024-27141
EUVD-2024-2438214.06.2024, 03:15
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request without authentication. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| toshibatec | e-studio-2521_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2020_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2520_nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2021_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2525_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3025_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3525_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3525_acg | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-4525_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-5525_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-5525_acg | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-6525_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-6525_acg | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2528-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3028-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3528-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3528-ag | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-4528-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-4528-ag | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-5528-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-6528-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-6526-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-6527-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-7527-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-6529-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-7529-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-9029-a | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-330-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-400-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2010-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2110-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2510-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2610-ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2015-nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2515-nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-2615-nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3015-nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3115-nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3515-nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-3615-nc | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-4515_ac | 𝑥 ≤ * | ADP |
| toshibatec | e-studio-4615_ac | 𝑥 ≤ * | ADP |
References