CVE-2017-2161

low
Published 2017-05-22 · Modified 2026-05-13
CVSS v3
3.5
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2
2.7
VIR risk
3.5

Description

FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.

Predictions

Exploit likelihood
35%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://www.toshiba-personalstorage.net/news/20170516a.htm

Application impact

VendorProductVersionsFixed
toshibaflashair{"endIncluding":"2.00.04"}

References

CWEs

CWE-425

Verify integrity in audit chain (admin only). AS-IS.