CVE-2017-2161
low
CVSS v3
3.5
CVSS v2
2.7
VIR risk
3.5
Description
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
Predictions
Exploit likelihood
35%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: vultures@jpcert.or.jp — http://www.toshiba-personalstorage.net/news/20170516a.htm
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| toshiba | flashair | {"endIncluding":"2.00.04"} | |
References
- http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html
- http://www.toshiba-personalstorage.net/news/20170516a.htm
- https://jvn.jp/en/jp/JVN46372675/index.html
- http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html
- http://www.toshiba-personalstorage.net/news/20170516a.htm
- https://jvn.jp/en/jp/JVN46372675/index.html
CWEs
CWE-425
Verify integrity in audit chain (admin only). AS-IS.