CVE-2023-34259 is a directory traversal vulnerability affecting Kyocera TASKalfa 4053ci printers (and potentially other models like d-copia253mf_plus) that allows authenticated attackers to read arbitrary files, including those requiring root privileges. This medium-severity vulnerability (CVSS 4.9) has a high confidentiality impact and is easily exploitable over the network with high privileges. While not currently on CISA's KEV catalog, its high EPSS score (0.92742) and the existence of a Nuclei template indicate a significant likelihood of exploitation, and it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2vg_s000.002.561CPE matchmatch criteria | cpe:2.3:o:kyocera:d-copia253mf_plus_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.