NA - CVE-2024-29146 - User passwords are decrypted and stored on...
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model...
NA - CVE-2024-29978 - User passwords are decrypted and stored on...
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model...
NA - CVE-2024-32151 - User passwords are decrypted and stored on...
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model...
NA - CVE-2024-33605 - Improper processing of some parameters of...
Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to...
"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and...
NA - CVE-2024-33616 - Admin authentication can be bypassed with some...
Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on...
NA - CVE-2024-34162 - The web interface of the affected devices is...
The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the...
NA - CVE-2024-35244 - There are several hidden accounts. Some of them...
There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to...
NA - CVE-2024-36248 - API keys for some cloud services are hardcoded...
API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective...
NA - CVE-2024-36249 - Cross-site scripting vulnerability exists in...
Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be...