CVE Feed

    Dashboard / CVE / CVE-2024-27141

    CVE-2024-27141

    Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request without authentication. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.

    Published:Jun 14, 2024
    Last Modified:Apr 15, 2026
    EPS:Jun 14, 2024
    EPSS Score:0.00102
    CVSS Score:5.9

    Affected Products

    Vendor
    Toshibatec
    Product
    E-studio-2010-ac
    Vendor
    Toshibatec
    Product
    E-studio-2015-nc
    Vendor
    Toshibatec
    Product
    E-studio-2020 Ac
    Vendor
    Toshibatec
    Product
    E-studio-2021 Ac
    Vendor
    Toshibatec
    Product
    E-studio-2110-ac
    Vendor
    Toshibatec
    Product
    E-studio-2510-ac
    Vendor
    Toshibatec
    Product
    E-studio-2515-nc
    Vendor
    Toshibatec
    Product
    E-studio-2520 Nc
    Vendor
    Toshibatec
    Product
    E-studio-2521 Ac
    Vendor
    Toshibatec
    Product
    E-studio-2525 Ac
    Vendor
    Toshibatec
    Product
    E-studio-2528-a
    Vendor
    Toshibatec
    Product
    E-studio-2610-ac
    Vendor
    Toshibatec
    Product
    E-studio-2615-nc
    Vendor
    Toshibatec
    Product
    E-studio-3015-nc
    Vendor
    Toshibatec
    Product
    E-studio-3025 Ac
    Vendor
    Toshibatec
    Product
    E-studio-3028-a
    Vendor
    Toshibatec
    Product
    E-studio-3115-nc
    Vendor
    Toshibatec
    Product
    E-studio-330-ac
    Vendor
    Toshibatec
    Product
    E-studio-3515-nc
    Vendor
    Toshibatec
    Product
    E-studio-3525 Ac
    Vendor
    Toshibatec
    Product
    E-studio-3525 Acg
    Vendor
    Toshibatec
    Product
    E-studio-3528-a
    Vendor
    Toshibatec
    Product
    E-studio-3528-ag
    Vendor
    Toshibatec
    Product
    E-studio-3615-nc
    Vendor
    Toshibatec
    Product
    E-studio-400-ac
    Vendor
    Toshibatec
    Product
    E-studio-4515 Ac
    Vendor
    Toshibatec
    Product
    E-studio-4525 Ac
    Vendor
    Toshibatec
    Product
    E-studio-4528-a
    Vendor
    Toshibatec
    Product
    E-studio-4528-ag
    Vendor
    Toshibatec
    Product
    E-studio-4615 Ac
    Vendor
    Toshibatec
    Product
    E-studio-5525 Ac
    Vendor
    Toshibatec
    Product
    E-studio-5525 Acg
    Vendor
    Toshibatec
    Product
    E-studio-5528-a
    Vendor
    Toshibatec
    Product
    E-studio-6525 Ac
    Vendor
    Toshibatec
    Product
    E-studio-6525 Acg
    Vendor
    Toshibatec
    Product
    E-studio-6526-ac
    Vendor
    Toshibatec
    Product
    E-studio-6527-ac
    Vendor
    Toshibatec
    Product
    E-studio-6528-a
    Vendor
    Toshibatec
    Product
    E-studio-6529-a
    Vendor
    Toshibatec
    Product
    E-studio-7527-ac
    Vendor
    Toshibatec
    Product
    E-studio-7529-a
    Vendor
    Toshibatec
    Product
    E-studio-9029-a

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High