CVE-2024-27143 is a critical vulnerability affecting Toshiba printers, allowing remote command execution as root due to insecure SNMP configuration using the private community string. With a CVSS score of 9.8, it presents a high risk of complete compromise (confidentiality, integrity, and availability) through a network-based attack with low complexity and no user interaction required. While difficult to exploit in isolation, it can be combined with other vulnerabilities for greater impact. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Toshiba Tec Corporation | Toshiba Tec E-Studio Multi-Function Peripheral (MFP) | see the reference URLCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.