Bp 70m45
Vendor:
First CVE: Dec 16, 2022 · Active for 3 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Bp 70m45 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 16, 2022
3 years ago
Most Recent CVE
Oct 25, 2024
637 days ago
CVE Severity & Scoring
Bp 70m4510 CVEs
40%
50%
10%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low1 (10.0%)
High2 (20.0%)
None7 (70.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47406CRITICAL Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. | Oct 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-42420HIGH Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages.
Crafte | Oct 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-47005HIGH Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted.
A non-administrative use | Oct 25, 2024 | 8.1 | 21 | NO | NO |
CVE-2024-45829HIGH Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerabil | Oct 25, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-43424HIGH Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability.
Crafted HTTP requests may cause affected products crashed. | Oct 25, 2024 | 7.5 | 21 | NO | NO |
CVE-2022-45796HIGH Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earli | Dec 16, 2022 | 7.2 | 19 | NO | NO |
CVE-2024-47801MEDIUM Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability.
Accessing a crafted URL which points | Oct 25, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-47549MEDIUM Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers.
Accessing a crafted URL | Oct 25, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-45842MEDIUM Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.
Unintended internal files may be retrieved when processing | Oct 25, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-48870MEDIUM Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability.
If crafted input is stored by an admi | Oct 25, 2024 | 4.8 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Bp 70m45
Top CWEs
Versions
No cataloged versions.