CVE Intelligence
Skip to main content
HIGH

CVE-2024-3496

CVE-2024-3496 — Authentication Bypass Vulnerability

Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for the affected products/models/versions, see the reference URL.

Published Updated Sources: cvelistV5, Toshiba

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

toshiba tec

51 products listed

CVSS base

8.8

HIGH

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

None

none · proof-of-concept · active

Automatable

No

can an attacker script all four kill-chain steps

Technical impact

Total

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Products (51)

toshiba tec e studio multi function peripheral mfpe studio 2525 ace studio 3025 ace studio 3525 ace studio 3525 acge studio 4525 ace studio 5525 ace studio 5525 acge studio 6525 ace studio 6525 acge studio 2528 ae studio 3028 ae studio 2521 ace studio 2020 ace studio 2520 nce studio 2021 ace studio 3528 ae studio 3528 age studio 4528 ae studio 4528 age studio 5528 ae studio 6528 ae studio 6526 ace studio 6527 ace studio 7527 ace studio 6529 ae studio 7529 ae studio 9029 ae studio 330 ace studio 400 ace studio 2010 ace studio 2110 ace studio 2510 ace studio 2610 ace studio 2015 nce studio 2515 nce studio 2615 nce studio 3015 nce studio 3115 nce studio 3515 nce studio 3615 nce studio 4515 ace studio 4615 ace studio 5015 ace studio 5115 ace studio 2018 ae studio 2518 ae studio 2618 ae studio 3018 ae studio 3118 ae studio 3118 ag

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
8.8CVSS 3.1HIGHcvelistV5

Weakness & attack patterns

  • CWE-288

Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.

  • T1083File and Directory Discovery
  • T1211Exploitation for Defensive Evasion
  • T1542.002Pre-OS Boot: Component Firmware

Detection

Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.

  • Search application, proxy, and WAF logs for requests touching /models/versions.

References

3 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.