CVE-2024-3496 describes a critical authentication bypass vulnerability affecting specific printer models, allowing unauthenticated attackers on the local network to gain full access to the printer's system information and upload malicious drivers. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the adjacent network (AV:A, AC:L, PR:N, UI:N) and can lead to high impact on confidentiality, integrity, and availability (C:H, I:H, A:H). While there is no evidence of active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), the low EPSS score suggests a low probability of exploitation in the wild. Despite the lack of current exploitation, the severity of the vulnerability necessitates prompt patching of affected devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Toshiba Tec Corporation | Toshiba Tec E-Studio Multi-Function Peripheral (MFP) | see the reference URLCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.