HIGH · 10.0

CVE-2012-1239

The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers...

Vulnerability Description

The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ToshibatecE-Studio-167 With Network Printer Kit Firmwaret282cn0j421
ToshibatecE-Studio-181 With Network Printer Kit Firmwaret282cn0j421
ToshibatecE-Studio-182 With Network Printer Kit Firmwaret282cn0j421
ToshibatecE-Studio-207 With Network Printer Kit Firmwaret282cn0j421
ToshibatecE-Studio-232 Firmwaret377sy0j354
ToshibatecE-Studio-2330C Firmwaret450sy0j302
ToshibatecE-Studio-2500C Firmwaret380sy0j354
ToshibatecE-Studio-255 Firmwaret470sy0j302
ToshibatecE-Studio-255P Firmwaret470sy0j302
ToshibatecE-Studio-281C Firmwaret410sy0j354
ToshibatecE-Studio-282 Firmwaret377sy0j354
ToshibatecE-Studio-2830C Firmwaret450sy0j302
ToshibatecE-Studio-3500C Firmwaret380sy0j354
ToshibatecE-Studio-3510C Firmwaret380sy0j354
ToshibatecE-Studio-351C Firmwaret410sy0j354
ToshibatecE-Studio-352 Firmwaret364sy0j354
ToshibatecE-Studio-3520C Firmwaret450sy0j302
ToshibatecE-Studio-355 Firmwaret470sy0j302
ToshibatecE-Studio-451C Firmwaret410sy0j354
ToshibatecE-Studio-452 Firmwaret364sy0j354

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1239?

CVE-2012-1239 is a vulnerability with a CVSS score of 10.0 (HIGH). The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers...

How severe is CVE-2012-1239?

CVE-2012-1239 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1239?

Check the references section above for vendor advisories and patch information. Affected products include: Toshibatec E-Studio-167 With Network Printer Kit Firmware, Toshibatec E-Studio-181 With Network Printer Kit Firmware, Toshibatec E-Studio-182 With Network Printer Kit Firmware, Toshibatec E-Studio-207 With Network Printer Kit Firmware, Toshibatec E-Studio-232 Firmware.