Toshiba Corporation
First CVE: Jun 14, 2024Active for: 2 years
43
CVEs Published
More CVEs Published than 54% of tracked CNAs
43.0
Avg CVEs / Year
More Avg CVEs / Year than 82% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 64% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Toshiba Corporation as a CNA, 0.0% affect products that Toshiba Corporation develops as a vendor.
100.0%
Self-reported: 0Third-party: 43
Of all the CVEs published that affect products developed by Toshiba Corporation, 0.0% are self-published by Toshiba Corporation as a CNA.
100.0%
Self-published: 0Published by other CNAs: 31
Trends Over Time
The number and severity of CVEs published by Toshiba Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2024
2 years ago
Most Recent CVE
Jun 14, 2024
772 days ago
Top CVEs
All CVEs published by Toshiba Corporation as a CNA, regardless of affected vendor or product.
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27172CRITICAL Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL. | Jun 14, 2024 | 9.8 | 41 | NO | NO |
CVE-2024-27173CRITICAL Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combin | Jun 14, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-27143CRITICAL Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will a | Jun 14, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-27144CRITICAL The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are | Jun 14, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-27174CRITICAL Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone | Jun 14, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-27145CRITICAL The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any inse | Jun 14, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3497HIGH Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/model | Jun 14, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-27162MEDIUM Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by th | Jun 14, 2024 | 6.1 | 26 | NO | NO |
CVE-2024-3496HIGH Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for the affected produc | Jun 14, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-27169HIGH Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the af | Jun 14, 2024 | 8.4 | 23 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA43 CVEs
33%
53%
14%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local27 (62.8%)
Network14 (32.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (4.7%)
Attack Complexity
Low26 (60.5%)
High17 (39.5%)
Unknown0 (0.0%)
User Interaction
None41 (95.3%)
Unknown0 (0.0%)
Required2 (4.7%)
Privileges Required
Low3 (7.0%)
High5 (11.6%)
None35 (81.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (43 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Toshiba Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Toshiba Corporation as a CNA — matched by CVE ID, not by organization name.