Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request without authentication. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.
History

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Toshibatec
Toshibatec e-studio-2010-ac
Toshibatec e-studio-2015-nc
Toshibatec e-studio-2020 Ac
Toshibatec e-studio-2021 Ac
Toshibatec e-studio-2110-ac
Toshibatec e-studio-2510-ac
Toshibatec e-studio-2515-nc
Toshibatec e-studio-2520 Nc
Toshibatec e-studio-2521 Ac
Toshibatec e-studio-2525 Ac
Toshibatec e-studio-2528-a
Toshibatec e-studio-2610-ac
Toshibatec e-studio-2615-nc
Toshibatec e-studio-3015-nc
Toshibatec e-studio-3025 Ac
Toshibatec e-studio-3028-a
Toshibatec e-studio-3115-nc
Toshibatec e-studio-330-ac
Toshibatec e-studio-3515-nc
Toshibatec e-studio-3525 Ac
Toshibatec e-studio-3525 Acg
Toshibatec e-studio-3528-a
Toshibatec e-studio-3528-ag
Toshibatec e-studio-3615-nc
Toshibatec e-studio-400-ac
Toshibatec e-studio-4515 Ac
Toshibatec e-studio-4525 Ac
Toshibatec e-studio-4528-a
Toshibatec e-studio-4528-ag
Toshibatec e-studio-4615 Ac
Toshibatec e-studio-5525 Ac
Toshibatec e-studio-5525 Acg
Toshibatec e-studio-5528-a
Toshibatec e-studio-6525 Ac
Toshibatec e-studio-6525 Acg
Toshibatec e-studio-6526-ac
Toshibatec e-studio-6527-ac
Toshibatec e-studio-6528-a
Toshibatec e-studio-6529-a
Toshibatec e-studio-7527-ac
Toshibatec e-studio-7529-a
Toshibatec e-studio-9029-a
CPEs cpe:2.3:h:toshibatec:e-studio-2010-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2015-nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2020_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2021_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2110-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2510-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2515-nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2520_nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2521_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2525_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2528-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2610-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-2615-nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3015-nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3025_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3028-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3115-nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-330-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3515-nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3525_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3525_acg:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3528-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3528-ag:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-3615-nc:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-400-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-4515_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-4525_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-4528-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-4528-ag:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-4615_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-5525_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-5525_acg:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-5528-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-6525_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-6525_acg:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-6526-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-6527-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-6528-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-6529-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-7527-ac:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-7529-a:-:*:*:*:*:*:*:*
cpe:2.3:h:toshibatec:e-studio-9029-a:-:*:*:*:*:*:*:*
Vendors & Products Toshibatec
Toshibatec e-studio-2010-ac
Toshibatec e-studio-2015-nc
Toshibatec e-studio-2020 Ac
Toshibatec e-studio-2021 Ac
Toshibatec e-studio-2110-ac
Toshibatec e-studio-2510-ac
Toshibatec e-studio-2515-nc
Toshibatec e-studio-2520 Nc
Toshibatec e-studio-2521 Ac
Toshibatec e-studio-2525 Ac
Toshibatec e-studio-2528-a
Toshibatec e-studio-2610-ac
Toshibatec e-studio-2615-nc
Toshibatec e-studio-3015-nc
Toshibatec e-studio-3025 Ac
Toshibatec e-studio-3028-a
Toshibatec e-studio-3115-nc
Toshibatec e-studio-330-ac
Toshibatec e-studio-3515-nc
Toshibatec e-studio-3525 Ac
Toshibatec e-studio-3525 Acg
Toshibatec e-studio-3528-a
Toshibatec e-studio-3528-ag
Toshibatec e-studio-3615-nc
Toshibatec e-studio-400-ac
Toshibatec e-studio-4515 Ac
Toshibatec e-studio-4525 Ac
Toshibatec e-studio-4528-a
Toshibatec e-studio-4528-ag
Toshibatec e-studio-4615 Ac
Toshibatec e-studio-5525 Ac
Toshibatec e-studio-5525 Acg
Toshibatec e-studio-5528-a
Toshibatec e-studio-6525 Ac
Toshibatec e-studio-6525 Acg
Toshibatec e-studio-6526-ac
Toshibatec e-studio-6527-ac
Toshibatec e-studio-6528-a
Toshibatec e-studio-6529-a
Toshibatec e-studio-7527-ac
Toshibatec e-studio-7529-a
Toshibatec e-studio-9029-a
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Toshiba

Published:

Updated: 2025-02-13T17:41:20.670Z

Reserved: 2024-02-21T02:11:53.249Z

Link: CVE-2024-27141

cve-icon Vulnrichment

Updated: 2024-08-02T00:27:59.773Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-14T03:15:09.700

Modified: 2024-11-21T09:03:56.060

Link: CVE-2024-27141

cve-icon Redhat

No data.